microsoft
Report a problem

Microsoft confirms Windows-Word attacks

Steven Parker   on 24 March 2008 - 10:03 · 11 comments & 8663 views

Advertisement (Why?)
Microsoft Corp. yesterday warned of a critical vulnerability that affects users of Word running on Windows 2000, XP and Server 2003 SP1 -- several weeks after one security company first reported an exploit and a day after a second vendor confirmed ongoing attacks.

In an advisory posted Friday, Microsoft acknowledged "public reports of very limited, targeted attacks" that exploit a bug in the Microsoft Jet Database Engine, a Windows component that provides data access to applications including Microsoft Access and Visual Basic.

According to Symantec Corp., however, the attacks Microsoft described used malicious Word 2000, 2002, 2003 and 2007 documents, which in turn call up the vulnerable Jet .dll.

"We believe that the issue being described [by Microsoft] is one described on March 20, 2008 by Elia Florio of Symantec Security Response," the security firm told customers of its DeepSight threat analysis network on Saturday. "He notes a recent discovery, by Panda Security, of a possible zero-day exploit observed in the wild."

News Source: ComputerWorld

Post a comment · Send to friend Comments · There are 11 additional comments
(1 reply) #1 Alex Bishop on 24 Mar 2008 - 10:55
I use open office
#1.1 vetneufuse on 24 Mar 2008 - 14:33
(Alex Bishop said @ #1)
I use open office


Yeah too bad this really is a vulnerability in the database engine that is included with windows, not really word per say... Using open office doesn't fix your Jet Database vulnerability...
(2 replies) #2 mrmckeb on 24 Mar 2008 - 11:22
Time to get Vista people It's obviously safer haha. This post isn't intended to cause a fight...
#2.1 kimatg on 24 Mar 2008 - 13:00
+1.

At least that's one sure thing MS improved (among many other features), for those who keep on insisting Vista is no better than XP.
#2.2 vetmarkjensen on 24 Mar 2008 - 13:21
(mrmckeb said @ #2)
Time to get Vista people It's obviously safer haha. This post isn't intended to cause a fight...

The Article
Microsoft said that users running Word on machines powered by Windows Vista and Windows Server 2003 SP2 are not at risk because those operating systems include a different version of Jet.

Looks like the solution isn't necessarily "Vista", but an updated version of the Microsoft Jet database engine.

If I can predict the future for a second here, let me guess that Microsoft will patch this with a Jet update, since that seems to be the source of the flaw, not the OS.
#3 strekship on 24 Mar 2008 - 14:22
Well from the sound of things you actually have to open the bad word documents first so it doesn't seem like a big deal.
(1 reply) #4 jamesVault on 24 Mar 2008 - 14:50
Windows Vista is NOT vulnerable. Yet another reason to prefer Vista over XP
#4.1 vetneufuse on 24 Mar 2008 - 16:28
(jamesVault said @ #4)
Windows Vista is NOT vulnerable. Yet another reason to prefer Vista over XP


Not really, just another reason not to use JET databases...
#5 Volatile on 24 Mar 2008 - 17:46
Vista isnt vulnerable YET.
#6 soldier1st on 24 Mar 2008 - 18:20
time to move on ppl to vista and stop the lame bashing of vista.
#7 Magallanes on 25 Mar 2008 - 13:34
You can jump to vista, spending a lot of money (and time) upgrading your system.
Or you can stop opening hideous files.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)