• On MovieTome: Leaked images from TRANSFORMERS 2?

December 14, 2006 11:50 AM PST

Attack code published for third Word flaw

A third security flaw in Microsoft Word has emerged, according to some security companies, and a researcher has published code for it that could be used to launch an attack.

Secunia and McAfee said Thursday that a buffer-overflow flaw in the word-processing application could crash a computer and ultimately let an outsider run code on a vulnerable PC.

But Microsoft said it could not confirm the existence of the vulnerability on Thursday, noting that it was still investigating the issue.

The problem is the third to arise in Word in less than two weeks. The other two zero-day vulnerabilities also involve memory corruption issues, according to a security advisory from Secunia. So far, these unpatched flaws have been used only for limited and targeted attacks, Microsoft has said.

"Up until now, it was only the victims of the attack, the attacker and Microsoft who knew how these flaws were exploited," said Thomas Kristensen, Secunia's chief technology officer.

With the third possible vulnerability, the situation could be more serious. A software analyst who calls himself "Disco Jonny" has published proof-of-concept code that appears to use the security hole.

"The impact of the file I released would be a crash in Microsoft Word. This file could be taken and turned into a functioning exploit by a person skilled enough," Disco Jonny said in an e-mail interview. "This could then lead to code, controlled by the person who sent or created the file, being run on the victim's machine in the context of the current user that is logged in."

As such, the proof-of-concept code could serve as a template for hackers to create a functioning malicious attack. It exploits a third flaw, but exactly how the code works is not clear, said Dave Marcus, security research and communications manager at McAfee.

Disco Jonny said that part of his problem in trying to be more specific about the source of the code is that he does not have access to information about the characteristics of the first two Word vulnerabilities. Microsoft has released a security advisory on one of those flaws, and a blog posting on the other, but these do not include much detail.

"From conversations with others, I am pretty sure that this bug is not related to the two current Word issues," Disco Jonny said. "This is a third, as yet unknown vulnerability in Microsoft Word. Without having the other two word issues to look at, I cannot state 100 percent either way."

See more CNET content tagged:
Microsoft Word, vulnerability, flaw, McAfee Inc., code

Add a Comment (Log in or register) 19 comments
MS Office IS a virus.
by Microsoft_Facts December 14, 2006 2:02 PM PST
MS Office. An easy to eradicate virus using Add/Remove Programs.
Reply to this comment View all 3 replies
This is part of Microsoft's migration to Office 2007 Plan
by slim-1 December 14, 2006 2:06 PM PST
Or you could install OpenOffice. Best installed in Linux but a Windows version is available too.
Reply to this comment View all 2 replies
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from CNET News sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right