Sophos

Talk to our experts

Find your local press contact

Resources

Sophos blogs

Info feeds

What are info feeds?

7 December 2006

Trojans spread via unpatched Microsoft Word vulnerability

Experts at SophosLabs™, Sophos's global network of virus, spyware and spam analysis centers, have warned internet users to take care when opening unsolicited Word documents, following the discovery of Trojan horses being distributed via an unpatched Microsoft security vulnerability.

Microsoft says in a security advisory that it is investigating the vulnerability which appears to allow hackers to launch attacks via Microsoft Word 2000, Microsoft Word 2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac, and Microsoft Word 2004 v. X for Mac. Microsoft Works 2004, 2005, and 2006 are also affected.

Sophos experts have issued protection against two Trojan horses, Troj/DwnLdr-FXG and Troj/DwnLdr-FXH, which have been seen being distributed via the unpatched flaw.

"It appears that hackers are deliberately creating malformed Word documents that result in a buffer overflow that can then run unauthorized code on the user's computer," said Graham Cluley, senior technology consultant for Sophos. "They can then tell the computer to download and run malware, such as these Trojan horses, opening the door for all kinds of malicious behavior."

At the time of writing Microsoft has published information about the vulnerability on its website, but has not yet issued a patch.

"So far the vulnerability does not appear to be being widely exploited. Nevertheless, Microsoft will be keen to build at patch for the security hole as quickly as possible, and computer users should exercise caution about which Word documents they choose to open," continued Cluley.

Sophos recommends that every IT manager responsible for security should consider subscribing to vulnerability mailing lists such as that operated by Microsoft at www.microsoft.com/technet/security/bulletin/notify.mspx.

Sophos continues to recommend companies protect their desktops and servers with automatically updated anti-virus protection and appropriate firewall defenses.

  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

About Sophos

More than 100 million users in 150 countries rely on Sophos as the best protection against complex threats and data loss. Sophos is committed to providing security and data protection solutions that are simple to manage, deploy and use and that deliver the industry's lowest total cost of ownership. Sophos offers award-winning encryption, endpoint security, web, email, and network access control solutions backed by SophosLabs - a global network of threat intelligence centers. With more than two decades of experience, Sophos is regarded as a leader in security and data protection by top analyst firms and has received many industry awards.

Sophos is headquartered in Boston, US and Oxford, UK. More information is available at www.sophos.com.

See also: