MS Word Vulnerabilities Reported on Exploit Sites

April 11, 2007

Microsoft says it has found no attacks attempting to exploit the reported Office vulnerabilities, but it is continuing to investigate.

Microsoft is investigating public reports of vulnerabilities in Microsoft Office.

Reports of several new security holes in Microsoft Office have been made public on known exploit sites. The company did not release specific information about the vulnerabilities, citing potential risk to users.

"Microsoft is not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time," said a spokesperson for the company, based in Redmond, Wash. "Microsoft will continue to investigate the public reports to help provide additional guidance for customers as necessary."

Postings about the vulnerabilities indicate that exploitation could lead to a program crash or the execution of arbitrary code.

Amol Sarwate, manager of vulnerability research at Qualys, a provider of on-demand security risk and compliance management solutions, based in Redwood Shores, Calif., said the widespread use of Microsoft Word makes the vulnerabilities even more threatening.

"Considering the prevalence of Microsoft Word, the fact that these vulnerabilities target unsuspecting users and also the consequence - total compromise of the system - I would say these vulnerabilities are very serious," Sarwate said. "In addition, zero-day targeted attacks - for CVE-2007-0870 - have amplified the need for a patch."

However, Sarwate added it is important to differentiate between proof-of-concept code and exploit code. "When POC - zero-day - code exists, is does raise the concern, but does not necessarily mean that exploit code will be released or that people will be exploited," he said.

Copyright 2007 by Ziff Davis Media, Distributed by United Press International


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 2.5 /5 (2 votes)


April 11, 2007 all stories

Comments: 0

2.5 /5 (2 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

  • Base Isolation Systems in Skyscrapers?
    created 14 hours ago
  • Need to interview a Computer Hardware Engineer for school project
    created 16 hours ago
  • transient heat transfer
    created 22 hours ago
  • Trying to adapt a fuel gage circuit
    created Nov 22, 2009
  • More from Physics Forums - General Engineering

Other News

NREL Uncovers Clean Energy Leaders State by State

NREL Uncovers Clean Energy Leaders State by State

Technology / Energy

created 4 hours ago | popularity 1 / 5 (1) | comments 1

(PhysOrg.com) -- That California and Texas still lead the United States in generating renewable energy probably is no surprise. But, NREL's 2009 State of the States report shows that several smaller states ...


Opera logo

Stable Opera 10.10 browser with Unite now available

Technology / Software

created 5 hours ago | popularity 4.7 / 5 (3) | comments 1

(PhysOrg.com) -- The web browser Opera 10.10 has been released as a stable version, and it has a number of new features to enhance the browsing experience, including "Unite", which is a group of applications ...


Intelligence inside metal components

Intelligence inside metal components

Technology / Engineering

created 2 hours ago | popularity 4.5 / 5 (2) | comments 0

Up to now, extreme production temperatures made it impossible to equip metallic components with RFID chips during the operating process. At Euromold in Frankfurt (Dec. 2-5), Germany, Fraunhofer researchers ...


Key scientist says politics behind stolen e-mails

Technology / Other

created 5 hours ago | popularity 1 / 5 (1) | comments 4

(AP) -- A leading climate change scientist said hackers breaking into a university's computer server and then posting documents online show the nasty politics of global warming.


Just in time for Black Friday: students turn iPhone into barcode scanner

Just in time for Black Friday: students turn iPhone into barcode scanner

Technology / Software

created 16 hours ago | popularity 4.7 / 5 (3) | comments 0

(PhysOrg.com) -- Comparing prices over the Internet has become a common practice for consumers. Now, just in time for Black Friday, a group of Missouri University of Science and Technology students is putting ...