main

Chinese Blogs Detail Zero-day Flaw in Microsoft Works

Daniel Fleshbourne   on 18 April 2008 - 14:45 · 8 comments & 4806 views

Advertisement (Why?)
Chinese-language blogs are detailing a zero-day vulnerability in Microsoft Works, the company's lower-end office productivity suite, according to security vendor McAfee. The vulnerability is within an ActiveX control for the Works' Image Server, wrote McAfee analyst Kevin Beets. A PC would need to visit a Web site engineered to exploit the flaw, Beets wrote.

A zero-day flaw is a software vulnerability that has become public knowledge but for which no patch is available. It is particularly dangerous since users are exposed from day zero until the day a vendor prepares a patch and notifies users it is ready. Proof-of-concept code was posted on a Chinese blog showing how the problem could cause Windows to crash, Beets wrote. Then, a few hours later, a working exploit appeared, which could allow malicious code to run on a machine.

View: The full story @ PCWorld

Post a comment · Send to friend Comments · There are 8 additional comments
#1 +GreyWolfSC on 18 Apr 2008 - 15:25
This isn't a zero-day flaw if it's the one posted about the other day. It was patched before anyone tried to exploit it.
#2 Frazell Thomas on 18 Apr 2008 - 15:42
Good thing no one uses Works...

OEMs should really ship Open Office instead of Works... Hell WordPad is better than works :|
(1 reply) #3 Burst404 on 18 Apr 2008 - 15:45
Now, is this another Chinese only bug? Because, if it is, I'm beginning to think Microsoft is racist... :|
#3.1 mocax on 18 Apr 2008 - 17:03
Maybe they're reluctant to hire chinese programmers due to recent spate of chinese spying.
#4 Xilo on 18 Apr 2008 - 18:49
Huh? People use Microsoft Works...?
#5 +Shadrack on 18 Apr 2008 - 20:07
I thought 'zero-day' was l33t h4ck32 speak.
#6 zhouij on 18 Apr 2008 - 21:00
lol this shows how bad the education system we have in the US. Now even the zero-day exploit hunting position has been outsourced to China. Apparently now they are doing that better and cheaper too.
#7 toadeater on 18 Apr 2008 - 21:59
All five users of MS Works shudder in terror.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)