![]() |
|
#1
|
||||
|
||||
|
Quote:
|
|
#2
|
|||
|
|||
|
Hello,
This is where OpenOffice comes into play. Mrk
__________________
http://www.dedoimedo.com All your base are belong to us Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA |
|
#3
|
||||
|
||||
|
|
|
#4
|
||||
|
||||
|
Microsoft Security Advisory (929433)
Vulnerability in Microsoft Word Could Allow Remote Code Execution Microsoft is investigating a new report of limited zero-day attacks using a vulnerability in Microsoft Word 2000, Microsoft Word 2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac, and Microsoft Word 2004 v. X for Mac, as well as Microsoft Works 2004, 2005, and 2006. In order for this attack to be carried out, a user must first open a malicious Word file attached to an e-mail or otherwise provided to them by an attacker. As a best practice, users should always exercise extreme caution when opening unsolicited attachments from both known and unknown sources. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. http://www.microsoft.com/technet/sec...ry/929433.mspx
__________________
Wilders
~Security Specialists~ Microsoft MVP - Consumer Security
|
|
#5
|
||||
|
||||
|
Quote:
lol, MrK you never miss an opportunity I guess you can't help it, Someone |
|
#6
|
|||
|
|||
|
Assuming that this exploit is similar to the others, here is a description of what happens:
Microsoft Word 0-day Vulnerability FAQ - September 2006 http://blogs.securiteam.com/?p=586 Q: Are there any visual effects informing about the infection? A: No. Q: Are there any changes to file system made by related malware? A: Yes. The file WINWORD.EXE is being dropped to the Windows %Systemroot% folder. When the related worm activates it will drop the following files: Windows\System32\clipbook.exe [30,720 bytes] Windows\System32\clipbook.dll [33,713 bytes] -------------------------------------------- Of course, no one would knowingly run such a .doc file But in case of an inadvertant instance, such remote code execution is easily blocked from installing executables by many products today. -rich ________________________________________________________________ "Talking About Security Can Lead To Anxiety, Panic, And Dread... Or Cool Assessments, Common Sense And Practical Planning..." --Bruce Schneier |
|
#7
|
||||
|
||||
|
Second vulnerability .....
|
|
#8
|
||||
|
||||
|
Exploit Code Targets Third Microsoft Zero-Day Word Bug
Quote:
|
|
#9
|
||||
|
||||
|
Exploit for Word also works with OpenOffice
Quote:
|
|
#10
|
|||
|
|||
|
Hello,
But the second part of the article: "It has not yet, however, been demonstrated that code can be injected via this weak point in OpenOffice. But there are unconfirmed reports that this is possible." The program crash versus System infection ... Mrk
__________________
http://www.dedoimedo.com All your base are belong to us Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|