Vulnerability in Word and Outlook

Icekingus

Level 1
Thread author
Aug 7, 2012
58
On March 24 Microsoft warned that attackers are exploiting a previously unknown security hole in Microsoft Word that can be used to foist malicious code if users open a specially crafted text file, or merely preview the message in Microsoft Outlook.

In a notice published today, Microsoft advised:

“Microsoft is aware of a vulnerability affecting supported versions of Microsoft Word. At this time, we are aware of limited, targeted attacks directed at Microsoft Word 2010. The vulnerability could allow remote code execution if a user opens a specially crafted [rich text format] RTF file using an affected version of Microsoft Word, or previews or opens a specially crafted RTF email message in Microsoft Outlook while using Microsoft Word as the email viewer. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.”

To be clear, Microsoft said the exploits it has seen so far attacking this vulnerability have targeted Word 2010 users, but according to Microsoft’s advisory the flaw is also present in Word 2003, 2007, 2013, Word Viewer and Office for Mac 2011.

Microsoft says it’s working on an official fix for the flaw, but that in the meantime affected users can apply a special Fix-It solution that disables the opening of RTF content in Microsoft Word. Microsoft notes that the vulnerability could be exploited via Outlook only when using Microsoft Word as the email viewer, but by default Word is the email reader in Microsoft Outlook 2007, Outlook 2010 and Outlook 2013.
 
  • Like
Reactions: cruelsister

Dubseven

Level 14
Verified
Aug 12, 2013
694
It's not the first Time .. so many vulnerability on Word and OpenOffice ...
 

Ink

Administrator
Verified
Jan 8, 2011
22,489
WordPad: Workaround for Word woes?

We have asked Microsoft if WordPad is vulnerable to the same zero day bug announced for Word. They are still researching and have not provided an answer. We don't have access to the exploit so we can't test it.

Either it is vulnerable or it isn't. If it is vulnerable then we would expect Microsoft to update the security bulletin to reflect this fact.

If it is not vulnerable, then it should serve as a reasonable workaround until a fix is provided. The "Fix it" Microsoft provided works by shutting off RTF support in Microsoft Word, so WordPad could be used in the interim, if it is not vulnerable. Microsoft would also update their advisory to note this.​

Read more - http://www.zdnet.com/wordpad-workaround-for-word-woes-7000027698/
 
  • Like
Reactions: Venustus

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top