Microsoft
The attacks use specially crafted Word files to target a vulnerability in Microsoft's Jet DB

Microsoft warns of new Office attack

Attackers take aim at database component

Written by Shaun Nichols in California

Microsoft has warned users to be vigilant after the discovery of a series of attacks on Office.

The attacks use specially crafted Word files to target a vulnerability in Microsoft's Jet DB, a database component used in the productivity suite.

The company issued an advisory outlining the attacks, which were classified as "very limited" and aimed at specific targets.

McAfee researcher Craig Schmugar suggested in a blog posting that the attacks could indicate a shift in strategy.

Attackers have typically exploited Microsoft Jet DB vulnerabilities through MDB files, and Microsoft has always stuck to its MDB files are unsafe story, wrote Schmugar. "Well that has changed," he added.

Microsoft said that Windows Vista and the recent Service Pack 1 upgrade are not vulnerable to the buffer overflow used in the attack. The Service Pack 2 version of Office 2003 is also immune.

The company is investigating the attacks, and has not yet decided whether to patch the flaw immediately or wait until next month's scheduled security update. Microsoft has advised users not to open files from untrusted sources.

The vulnerability allows an attacker to access the system with the rights of the current user, and Microsoft said that administrators can minimise this risk by putting controls on non-administrator accounts.

Further reading

Windows Vista SP1 causing PC glitches

Users complain of service pack gremlins   More...

UK Xbox 360 sales soar 40 per cent

Price cut boosts sales of Microsoft console   More...

Red Hat releases free security code

Beat that, says Linux vendor   More...

Microsoft updates Excel security patch

Last week's fix caused performance problems   More...

Related articles

Attack exploits 'unsafe' Windows files

Access Database files used for attacks   More...

Windows 2000 flaw highlights slow Patch Tuesday

Vista and XP spared from most dangerous vulnerabilities   More...

Microsoft updates Office Jet attack advisory

Company provides background on new Office attack   More...

Security flaw hits MSN Messenger

Vulnerability puts users at risk of arbitrary code execution   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

13 May 2008

3.06 MBBloody students, goodbye to Dixons and hacking excuses More...

BusinessGreen.com podcast logo

13 May 2008

1.82 MBEco-Entrepreneur introduction More...

12 May 2008

2.4 MBMicrosoft's battles, data breach fines and website rip-offs More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

BlackBerry Bold

RIM unveils slimmed-down BlackBerry Bold

New handset due this summer   More...

BlackBerry Bold

BlackBerry Bold takes on 3G iPhone

New models go head-to-head, says analyst   More...

Advertisement

HP

HP 'in talks' to buy EDS

Company offering upwards of $12bn   More...

Virgin Media

Virgin prepares 50Mbps launch in 2008

Successful trial clears network for higher speeds   More...

Advertisement