Welcome | Sign In
ECommerceTimes.com
Malware

Security Hole in Microsoft Word Threatens Millions

Print Version
E-Mail Article
Reprints
Security Hole in Microsoft Word Threatens Millions

"Users, home and corporate, need to understand that even if an e-mail appears to come from someone they know, it may not have actually been sent by that person," warned Randy Abrams, director of technical education at ESET. "Attachments that are not asked for or expected should not be opened prior to confirming with the sender that they actually did send the attachment and why."


10 Steps to a Successful CRM Implementation
Follow these 10 steps to help ensure that your CRM implementation is a success, from the planning stages to post-deployment improvements. Get the free white paper.

Microsoft (Nasdaq: MSFT) is currently investigating a vulnerability in certain editions of its Word Software that could open millions of unprotected PCs to hacker attacks.

The vulnerability affects Word 2000, 2002, 2003, Word Viewer 2003, Word 2004 for Mac, and Word 2004 version X for Mac. The free applications of Microsoft Works -- versions 2004, 2005 and 2006 -- are also vulnerable.

How Big?

As Microsoft is releasing little data, the scope of the problem is unclear. As few as 300,000 users out of a potential universe of millions have sufficient firewall and antivirus defenses in place to protect against incursions, estimates Ryan Sherstobitoff, product technology officer for Panda Software.

Even though the flaw is widespread in terms of the number of products affected, the impact is not likely to be on the scale of a Blaster or Slammer worm, Randy Abrams, director of technical education at ESET, told TechNewsWorld. In those cases, code was executed without user interaction.

"This is really more of an incident that should be used to remind people to be cautious in handling attachments, rather than a high -profile threat," he said.

Standard Precautions

Until a patch is released, Microsoft and security experts are cautioning users not to open unexpected documents, especially those from unknown sources.

"Users, home and corporate, need to understand that even if an e-mail appears to come from someone they know, it may not have actually been sent by that person," Abrams warned. "Attachments that are not asked for or expected should not be opened prior to confirming with the sender that they actually did send the attachment and why."

The primary consumer attack vectors will likely be documents sent to people that claim to contain user names and passwords for porn sites; lists of activation codes for desirable software; information about a consumer's bank, stock or other financial account; pictures of celebrities; or jokes, Abrams said.

"History has taught us that these are highly successful social engineering tactics," he observed. "The fact that Word documents are very commonly exchanged make this vulnerability of concern.However, other means of tricking users into installing malicious software are effective enough that malware writers may not see a need to expend energy on an attack that is likely to gain only marginal returns."

More Mac users than usual might fall victim, since this user group is unaccustomed to malware and may not be as vigilant, Sherstobitoff told TechNewsWorld, noting that it is generally unusual for Mac software to be affected.

"It is more difficult to run arbitrary code on the Mac's underlying kernel than it is with a Windows OS," he pointed out.

Corporations at Risk

Even though corporations are better prepared than individual users for online malware, their systems may be at greater risk for attack, said Abrams.

"For financially motivated attackers, it is not important to be able to exploit a million machines. Simply compromising one machine on a network can be enough to gain access to proprietary corporate information. It is likely that this will be a small, but costly, attack vector," he predicted.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Google Bends a Little Toward Nexus One Customers
February 09, 2010
Google appears to be taking some customer objections to the Nexus One seriously, although its overtures may not be enough to warm customers to its new business model. For one thing, it has reduced the fee it would charge for early termination to $150, but customers would have to pay T-Mobile an ETF as well. It has also set up a direct support line for orders -- but not for tech support.
Does 'Nimble' Pricing Suggest iPad Won't Move?
February 09, 2010
Indications that Apple may lower the price of its new iPad have surfaced -- even though its not yet available for sale -- suggesting that the company may not be certain it hit the sweet spot for consumers. One big inhibitor for a lot of prospective buyers is the extra monthly charge for WiFi and 3G connectivity.
Report: iPad Will Propel Tablets Into Mainstream Use
February 08, 2010
Will Apple's iPad do for tablets what its iPod did for MP3 players? Quite possibly. The tablet market will grow quickly on the heels of the iPad's release, according to In-Stat, which forecasts 50 million of the devices will ship in 2014. Others are less optimistic, though. Notably, consumer interest in buying an iPad did not increase as a result of the product's unveiling, according to a Retrevo survey.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
9 Proven Techniques to Double your Sales.
Free eBook: Click here to download today.
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network