Follow Us

Word attack in the wild

Exploit Wednesday for real this time.

An attack that exploits a vulnerability in Word has been discovered, just one day after Microsoft pushed out a patch.

Symantec reported it had obtained a suspicious document that crashed every version of Word except the newest, Word 2007. After it examined the document, Symantec found that it included shell code and three pieces of malware.

Among its more surprising findings: Symantec found that the document had been created with the edition of Word included with Office for Mac 2004.

Microsoft patched a critical vulnerability in multiple editions of the word processor on this week's Patch Tuesday. Symantec put the two together. "Taking a closer look at that vulnerability, we confirmed that this document was in fact exploiting the same vulnerability," researcher Orla Cox said on the company's blog.

Even though Microsoft acknowledged on Tuesday that attacks had already been seen in the wild, Symantec remarked on the finding. "In our experience, the exploitation of such vulnerabilities tends to be very targeted in nature," said Cox.

It's not unusual, however, for exploits to appear soon after a vendor posts a patch. The practice, dubbed "Exploit Wednesday" to match "Patch Tuesday", has been debunked by some, however, as part myth.

Updates to the Windows versions of Word can be obtained via Microsoft Update or Office Update, while the patch for the Mac edition is included in the 11.3.8 update to Office 2004 available on the website of Microsoft's Macintosh development team.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *