Attack exploits 'unsafe' Windows files

Access Database files used for attacks

Written by Shaun Nichols in California

The US Computer Emergency Response Team (US-CERT) is warning users to be vigilant of attacks using Microsoft Access Database (MDB) files.

US-CERT said that it has received reports of attacks targeting the vulnerability in the wild. If exploited, the flaw allows an attacker to remotely execute code on the target machine.

A Microsoft spokesperson would not directly confirm the report, but said that the company is investigating reports of an attack targeting MDB files.

The spokesperson told vnunet.com that even without the vulnerability, MDB files are among those classified as 'unsafe' file types that can be used in attacks.

Though it may sound foreboding, the term simply refers to files that allow for automated actions to run on a user's machine. Other file types classified by Microsoft as 'unsafe' include executables (.exe) and Word documents (.doc).

US-CERT recommends that users reduce the risk of the vulnerability by avoiding suspicious email attachments. The group also recommends that administrators set email filters to block attached file types classified as 'unsafe'.

The reports come just as Microsoft is releasing its final scheduled security update for 2007. The company did not rule out releasing an out-of-schedule patch if the attacks persist.

Tags:

Further reading

Related articles

Microsoft warns of new Office attack

Attackers take aim at database component   More...

Attack code targets unpatched Adobe Reader flaw

Time running out for Adobe to patch 'critical' vulnerability   More...

RealPlayer flaw raises security flags

Be wary of unknown files, say experts   More...

Zero-day flaw hits Windows XP

Vulnerabilities in MFC42 and MFC71 could allow remote code execution   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

12 May 2008

2.4 MBMicrosoft's battles, data breach fines and website rip-offs More...

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

BlackBerry Bold

RIM unveils slimmed-down BlackBerry Bold

New handset due this summer   More...

BlackBerry Bold

BlackBerry Bold takes on 3G iPhone

New models go head-to-head, says analyst   More...

Advertisement

HP

HP 'in talks' to buy EDS

Company offering upwards of $12bn   More...

Virgin Media

Virgin prepares 50Gbps launch in 2008

Successful trial clears network for higher speeds   More...

Advertisement