<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>ewhbc-cllc.org Blog</title>
	<link>http://ewhbc-cllc.org/blog</link>
	<description>Information Technology Discussions, Questions and Answers</description>
	<pubDate>Tue, 20 Mar 2007 10:47:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.2</generator>
	<language>en</language>
			<item>
		<title>Be careful opening MS Word documents received in emails.</title>
		<link>http://ewhbc-cllc.org/blog/2006/12/12/be-careful-opening-ms-word-documents-received-in-emails/</link>
		<comments>http://ewhbc-cllc.org/blog/2006/12/12/be-careful-opening-ms-word-documents-received-in-emails/#comments</comments>
		<pubDate>Tue, 12 Dec 2006 17:39:32 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Technology Education</category>
	<category>Virus Worms and Vulnerabilities</category>
		<guid isPermaLink="false">http://ewhbc-cllc.org/blog/2006/12/12/be-careful-opening-ms-word-documents-received-in-emails/</guid>
		<description><![CDATA[Microsoft Confirms New Word Vulnerability



Elizabeth Millard, newsfactor.com 52 minutes ago
Microsoft has confirmed that criminals are e-mailing Word attachments that contain malicious code, with two vulnerabilities in the ubiquitous word-processing software now being exploited.
The separate acknowledgements of the two flaws came about a week apart. Both flaws put users at risk. In the most recently reported [...]]]></description>
			<content:encoded><![CDATA[<h1>Microsoft Confirms New Word Vulnerability</h1>
<p><!-- END HEADLINE --></p>
<div id="ynmain"><!-- BEGIN STORY BODY --></p>
<div id="storybody">
<div class="storyhdr">Elizabeth Millard, <a href="http://us.rd.yahoo.com/dailynews/nf/tc_nf/byline/48699/21246793/SIG=10r33ca9a/*http://www.newsfactor.com">newsfactor.com</a><em class="recenttimedate"> 52 minutes ago</em></div>
<p>Microsoft has confirmed that criminals are e-mailing Word attachments that contain malicious code, with two vulnerabilities in the ubiquitous word-processing software now being exploited.</p>
<p>The separate acknowledgements of the two flaws came about a week apart. Both flaws put users at risk. In the most recently reported vulnerability, a zero-day flaw, an attacker can run unauthorized software on a victim&#8217;s machine simply by having the message&#8217;s recipient open a Word document.</p>
<p>The vulnerability has been rated &#8220;extremely critical&#8221; by security firm Secunia because of its potential danger to users.</p>
<p>A similar bug was reported last week. According to Microsoft, neither bug will be patched in the latest round of software updates, known as Patch Tuesday. Microsoft has noted that both flaws are being exploited only on a very limited and targeted basis.</p>
<p>Office Mate</p>
<p>Over the past year, hackers have been increasingly interested in finding flaws in Microsoft&#8217;s Office suite. The popularity of applications like Excel and PowerPoint have led attackers to find flaws in those programs because they can reach such large numbers of users.</p>
<p>The recent Word flaws runs the gamut of major versions of the software &#8212; including Word 2000, Word 2002, Word 2003, and Word Viewer 2003 &#8212; but does not affect Word 2007.</p>
<p>In an advisory, Microsoft noted that the most recent vulnerability is different from the other Word flaw found last week, also a zero-day vulnerability for which there is no patch, but did not go into specifics.</p>
<p>&#8220;Do not open or save Word files that you receive from untrusted sources or that you receive unexpectedly from trusted sources,&#8221; Microsoft warned.</p>
<p>Patch Work</p>
<p>Although Microsoft has drawn criticism in the blogosphere for not being speedier with a patch for the problems, Secunia Chief Technology Officer Thomas Kristensen noted that fixing a flaw like this in a program as popular as Word might take some time.</p>
<p>&#8220;These patches are not always straightforward,&#8221; he said, adding that first Microsoft has to analyze and confirm the problem, then examine the code before creating a fix to change the code behavior.</p>
<p>After creating the patch, the company has to conduct several tests globally, given Word&#8217;s prevalence in the marketplace. &#8220;Unfortunately, all of this takes time, but it&#8217;s necessary,&#8221; Kristensen said. &#8220;In the meantime, customers are vulnerable.&#8221;</p>
<p>Secunia is recommending that users be particularly diligent about not opening attachments from people they do not know.</p>
<p>&#8220;The good news is that the distribution has been limited, so that makes widespread infection less likely,&#8221; said Kristensen. &#8220;Then again, we&#8217;re talking about criminals, and you don&#8217;t know where they&#8217;re going to surface next time.&#8221;</div>
</div>
]]></content:encoded>
			<wfw:commentRSS>http://ewhbc-cllc.org/blog/2006/12/12/be-careful-opening-ms-word-documents-received-in-emails/feed/</wfw:commentRSS>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 2.637 seconds -->
