Microsoft warned Tuesday that attackers are actively targeting Windows Vista, as well as Microsoft Office 2003 through 2010, with an attack that would give hackers the same rights as the victim.
“The exploit requires user interaction as the attack is disguised as an email requesting potential targets to open a specially crafted Word attachment,” Microsoft said. “If the attachment is opened or previewed, it attempts to exploit the vulnerability using a malformed graphics image embedded in the document. An attacker who successfully exploited the vulnerability could gain the same user rights as the logged-on user.”