Archive Pages Design$type=blogging

Microsoft: 0Day Exploit Targeting Word, Outlook

Microsoft warned today that attackers are exploiting a previously unknown security hole in Microsoft Word that can be used to foist maliciou...



Microsoft warned today that attackers are exploiting a previously unknown security hole in Microsoft Word that can be used to foist malicious code if users open a specially crafted text file, or merely preview the message in Microsoft Outlook.

In a notice published today, Microsoft advised:

Microsoft is aware of a vulnerability affecting supported versions of Microsoft Word. At this time, we are aware of limited, targeted attacks directed at Microsoft Word 2010. The vulnerability could allow remote code execution if a user opens a specially crafted [rich text format] RTF file using an affected version of Microsoft Word, or previews or opens a specially crafted RTF email message in Microsoft Outlook while using Microsoft Word as the email viewer. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.

To be clear, Microsoft said the exploits it has seen so far attacking this vulnerability have targeted Word 2010 users, but according to Microsoft’s advisory the flaw is also present in Word 2003, 2007, 2013, Word Viewer and Office for Mac 2011.

Microsoft says it’s working on an official fix for the flaw, but that in the meantime affected users can apply a special Fix-It solution that disables the opening of RTF content in Microsoft Word. Microsoft notes that the vulnerability could be exploited via Outlook only when using Microsoft Word as the email viewer, but by default Word is the email reader in Microsoft Outlook 2007, Outlook 2010 and Outlook 2013.

One way to harden your email client is to render emails in plain text. For more information on how to do that with Microsoft Outlook 2003, 2007, 2010 and 2013, see these two articles.

COMMENTS

Name

ALL android Apple articles Build free website CSS Downloads DVD exclusive facebook freebies fun games giveaways google HTML internet iPhone iPhone 6 iPhone 6 Plus iPhone 6s kali linux leaks linux Microsoft News Offers opensource php psd Quick Tips Samsung Series Skype Templates Tips tools Tooltips tricks Tutorials Videos VPN windows Youtube
false
ltr
item
Sticky TUTS | When Technology meets pleasure: Microsoft: 0Day Exploit Targeting Word, Outlook
Microsoft: 0Day Exploit Targeting Word, Outlook
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBjgK8ImPWfs9k_vBwFMrbxFg-71sLuMJ_dsvJbvbGjEDtjbKqvSMEPcABPN2lcnfaASKXGv0vBhTL7VyvCRklnOj8gCA8S-fChYz5wmL1_Pqoi-2I_pWEv-o0jCbHl9CmpERj61W9HNo/s1600/microsoft_office_system_logo-300x226.jpg
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBjgK8ImPWfs9k_vBwFMrbxFg-71sLuMJ_dsvJbvbGjEDtjbKqvSMEPcABPN2lcnfaASKXGv0vBhTL7VyvCRklnOj8gCA8S-fChYz5wmL1_Pqoi-2I_pWEv-o0jCbHl9CmpERj61W9HNo/s72-c/microsoft_office_system_logo-300x226.jpg
Sticky TUTS | When Technology meets pleasure
https://stickytuts.blogspot.com/2014/03/microsoft-0day-exploit-targeting-word.html
https://stickytuts.blogspot.com/
http://stickytuts.blogspot.com/
http://stickytuts.blogspot.com/2014/03/microsoft-0day-exploit-targeting-word.html
true
1514106023108819307
UTF-8
Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago