Home > Security News > Zero-day threat targets Microsoft Word
Security News:
EMAIL THIS

Zero-day threat targets Microsoft Word

By Eric B. Parizo, News Editor
19 May 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Targeted exploit code has been discovered in the wild that takes advantage of Microsoft Word to open a backdoor for attackers.

Cupertino, Calif.-based antivirus giant Symantec Corp. this morning informed customers of its DeepSight Threat Management System that it has raised its ThreatCon level from 1 to 2 (on a scale of 4) as a result of the exploit, currently known as Trojan.Mdropper.H.

In its message to customers, Symantec said the zero-day exploit arrives as a Word document attached to an email. Vincent Weafer, senior director at Symantec's Security Response unit, said the document appears to be of Japanese origin and includes text summarizing a recent U.S.-Asian political summit.

Weafer said inside the document's OLE structure is a dropper program called Backdoor.Ginwui. Once a victim opens the document, that program creates a backdoor for attackers to exploit the system using a previously unknown vulnerability.

"The backdoor will point to an IP address in Asia to say it's available," Weafer said. "The dropper and the backdoor are fairly standard, but this is a targeted attack. We're not seeing it as spam."

In fact, Weafer added, Symantec currently knows of only one customer that has been affected by the exploit. Yet he said the antivirus giant chose to raise its ThreatCon level because it is an example of a highly dangerous attack to which enterprises could easily fall victim.

"Even though we're not talking about volume, this kind of targeted attack is something [our customers] care about," Weafer said. "This is the type of attack they worry about. Something that leverages a zero-day vulnerability, is targeted and seeks out specific information."

The SANS Internet Strom Center reports that the unnamed organization that was targeted received a single e-mail that was sent to specific individuals and crafted to look like it originated from the organization's own domain.

The exploit targets Microsoft Word 2003, but it causes Word 2000 to crash apparently without triggering the backdoor exploit.

A Microsoft spokesman confirmed that the software giant is investigating "new public reports of a zero-day attack using a vulnerability in Microsoft Word XP and Microsoft Word 2003."

"Microsoft is completing development of a security update for Microsoft Word that addresses this vulnerability," Microsoft said in a statement. "The security update is now being finalized through testing to ensure quality and application compatibility and is on schedule to be released as part of the June security updates on June 13, 2006, or sooner as warranted."

Weafer said Symantec's research suggests the exploit is merely the most recent in a string of similar attacks. He said a number of other recent targeted efforts have used similar methods to exploit other Microsoft applications such as Excel, Access or Outlook. Plus this new exploit attempts to contact the same IP address in Asia as in previous exploits.

Symantec recommends that organizations block .doc Word email attachments at the network perimeter. Weafer suggested converting documents to safer formats, such as .rtf.

"Furthermore," the vendor said in its email to customers, "extreme caution should be exercised while processing Microsoft Word attachments received as an unexpected email attachment."

Tags: Securing Productivity ApplicationsMalware, Viruses, Trojans and SpywareEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Securing Productivity Applications
How to detect software tampering
Adobe fixes 29 flaws in Acrobat, Reader
Adobe warns of critical update for Reader, Acrobat 9.1.3
Why should we place data files on a separate partition than the OS?
Adobe updates ColdFusion, JRun, Flex
Serious Adobe Flash flaw being exploited
Adobe acknowledges serious Flash zero-day vulnerability
Adobe issues security advisory for Flash zero-day flaw
When to use the service features of the Metasploit hacking tool
How to manage patches for Adobe

Malware, Viruses, Trojans and Spyware
Schneier-Ranum Face-Off: Is antivirus dead?
Modern malware, stealthy botnets, adapt quickly, expert says
Computer worm infections up, scareware antivirus down, Microsoft says
Web-based attacks skyrocket, pirating sites surge, security firms say
Mini guide: How to remove and prevent Trojans, malware and spyware
Kaspersky system analyzes malicious URLs on Twitter for malware
Silon malware intercepts Internet Explorer sessions, steals credentials
Breach forces payroll service provider PayChoice to shut down again
RSA research underscores problem tracking cybercriminals
Conficker analysis finds P2P coding limited, less sophisticated

Email and Messaging Threats (spam, phishing, instant messaging)
Messaging security risks have upper hand on solutions
Web-based attacks skyrocket, pirating sites surge, security firms say
Pushdo botnet uses Facebook to spread malicious email attachment
Scareware report highlights successful business model
How to prevent phishing attacks with social engineering tests
Phishing protection begins with training, antiphishing evangelist
Phishing attacks to remain a major problem, say security experts
Barracuda acquires Purewire expanding Web security reach
FBI raids phishing crime ring, nearly 100 arrested
Massive phishing scheme affects Microsoft Hotmail accounts
Email and Messaging Threats (spam, phishing, instant messaging) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
sheepdip  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts