23 May 2006 | 3,380 views

Trojan for the Word Vulnerability in the Wild

Check Your Web Security with Acunetix

We all knew it was just a matter of time until the ‘thing’ was out.

PandaLabs has detected the appearance of 1Table.A, a malicious code that exploits a recently detected critical vulnerability in Microsoft Word, and which also affects versions of MS Office 2003 and XP.

Microsoft confirmed today the existence of this vulnerability and apparently is working on a hotfix.

This security problem allows the execution of code on affected systems and, more dangerously, allows the construction of malicious code which is indistinguishable at first glance from a normal Word file.

That’s more than enough to get 70%* of the people who use Microsoft Office to download and execute the file. If they open .BAT, .COM and .EXE, opening a .DOC is everyday work.

This attack is not limited to .DOC files, still, they will be the most used extension. It can take place with a .XLS file with an embedded Word document.

1Table.A – the new trojan – is detected by most of the antivirus software, however, user’s should have they’r eyes open until patch is released by Microsoft (even if they don’t consider it critical)

Source: NHS

* 80% of the statistics are made on the spot!

Digg This Article

Advertisements



Recent in Exploits/Vulnerabilities:
- The Jeep HACK – What You Need To Know
- Dharma – Generation-based Context-free Grammar Fuzzing Tool
- Hacking Team Hacked – What You Need To Know

Related Posts:
- Microsoft Word 0-day Exploits – QUESTION.DOC
- Custom Trojans – Isn’t it Old News?
- Adobe Patches Latest Flash Zero Day Vulnerability

Most Read in Exploits/Vulnerabilities:
  • Learn to use Metasploit – Tutorials, Docs & Videos - 231,326 views
  • AJAX: Is your application secure enough? - 119,635 views
  • eEye Launches 0-Day Exploit Tracker - 85,264 views


  • Low-cost VPS Hosting

    Comments are closed.