Slashdot Mirror


Microsoft Issues Zero-Day Attack Alert For Word

0xbl00d writes "Eweek.com is reporting a new Microsoft Word zero-day attack underway. Microsoft issued a security advisory to acknowledge the unpatched flaw, which affects Microsoft Word 2000, Microsoft Word 2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac and Microsoft Word 2004 v. X for Mac. The Microsoft Works 2004, 2005 and 2006 suites are also affected because they include Microsoft Word. Simply opening a word document will launch the exploit. There are no pre-patch workarounds or anti-virus signatures available. Microsoft suggests that users 'not open or save Word files,' even from trusted sources."

45 of 483 comments (clear)

  1. Microsoft Recommends.. by sylvainsf · · Score: 5, Funny

    That the business world just stop for a few minutes(days, weeks) while they fix this.

    1. Re:Microsoft Recommends.. by Anonymous Coward · · Score: 5, Funny

      I wish Microsoft were a person. Then I could go up and kick that person in the nuts.

    2. Re:Microsoft Recommends.. by JoGlo · · Score: 5, Funny

      Oooooh! She wouldn't like that!

      --
      Will those of you who think that you know what you are doing, get out of the way of those of us who know what we are doi
    3. Re:Microsoft Recommends.. by Brewskibrew · · Score: 4, Funny

      Get a stone tablet and a chisel. Those will also translate Word documents as well as make handy weapons for when your Microsoft Account Manager pops into your office.

      --
      For sale: Signature. One owner. Low miles. Always garaged. New punctuation, just installed!
    4. Re:Microsoft Recommends.. by Anonymous Coward · · Score: 4, Funny

      Quarriers! Quarriers! Quarriers!

    5. Re:Microsoft Recommends.. by OldManAndTheC++ · · Score: 3, Funny

      Get a stone tablet and a chisel.

      Actually Microsoft is going to release a product for that very format.

      They plan to call it Microsoft Word 2007 BC.

      And in an even weirder twist, because the product release schedule slipped they had to change the original name: Microsoft Word 2009 BC

      --
      Soylent Green is peoplicious!
    6. Re:Microsoft Recommends.. by Anonymous Coward · · Score: 1, Funny

      I always wanted a pet bear...

    7. Re:Microsoft Recommends.. by volpe · · Score: 2, Funny

      Why don't just use latex?

      You're confused. Condoms work on an entirely different kind of virus.

  2. Looks like a long work day tomorrow by filesiteguy · · Score: 4, Funny

    If I can't even open my friends' documents then what am I - as a manager to do?

    Oh, wait - I don't do anything anyway and my life revolves around Excel.

    Nevermind.

    1. Re:Looks like a long work day tomorrow by thrillseeker · · Score: 5, Funny

      By the way, am I alone in thinking that it would be a good idea to have OpenOffice.org re-written in the Java language?

      very alone ...

    2. Re:Looks like a long work day tomorrow by aibrahim · · Score: 3, Funny

      > I have two words for you: As long as you PowerPoint, you're all set.

      >> That's a lot more than two words. Perhaps you should have used the preview button?

      Never attended a presentation ? Thats actually a Powerpoint users notion of two words.

      --

      Don't post innacurate information
      If you do, I swear by my pretty floral bonnet I will end you.
    3. Re:Looks like a long work day tomorrow by Jello+B. · · Score: 5, Funny

      Obviously. This is Slashdot, not IRC.

    4. Re:Looks like a long work day tomorrow by mollymoo · · Score: 5, Funny
      If I can't even open my friends' documents then what am I - as a manager to do?

      I don't know where you got your MBA, but the low-hanging fruit is there to be picked - in simple terms, you need to synergize new communications opportunities by leveraging existing facilities. Incentivize your staff to maximally capitalize on the benefits of an approach which unifies the output of global arboreal facilities, exsting team-member dexterity and some pens.

      --
      Chernobyl 'not a wildlife haven' - BBC News
    5. Re:Looks like a long work day tomorrow by poopie · · Score: 3, Funny

      By the way, am I alone in thinking that it would be a good idea to have OpenOffice.org re-written in the Java language? The Java license is now very appealing.

      Umm... I think some out of work java programmers are with you. Oh, and I think you've got the support of memory chip manufacturers and makers of quad core CPUs.
  3. Lets see... by jlarocco · · Score: 4, Funny

    So let me get this straight... For the time being the only safe Word files are new files that other people don't need to open?

    But hey, you saved a ton of money on retraining costs.

  4. Good Advice by antonyb · · Score: 4, Funny

    Microsoft suggests that users 'not open or save Word files,' even from trusted sources."

    Good general advice, really. They should put that on the Office packaging, like on a packet of cigarettes.

    ant

  5. Not open or save? by Aardpig · · Score: 3, Funny

    So, Microsoft are basically telling us to stop using Word? Sounds like great advice to me -- cheers, Bill!

    --
    Tubal-Cain smokes the white owl.
  6. Re:So many versions, same bug by jibjibjib · · Score: 2, Funny

    Making the Ribbon, and then congratulating themselves on how cool it looks, and then making advertisements with people with dinosaur heads.

  7. Comment removed by account_deleted · · Score: 4, Funny

    Comment removed based on user account deletion

  8. Re:So many versions, same bug by symbolset · · Score: 2, Funny

    You forgot to mention the Vista sound. The put tons of effort into that.

    --
    Help stamp out iliturcy.
  9. Microsoft Marketing... by SirKron · · Score: 3, Funny

    This is a new spin to upgrade to their new Office 2007 product line.

  10. Oh, great! by Marsala · · Score: 5, Funny

    Yet ANOTHER feature Word has that OpenOffice doesn't. :(

  11. Re:Article Summary is Flamebait by Perseid · · Score: 5, Funny

    Yeah, they taught me in school that latex was a good way to guard from viruses.

  12. Re:Just to be safe.. by assassinator42 · · Score: 3, Funny

    Good thing I connect via WiFi.

  13. This aughta make FINALS more interesting... by surfcow · · Score: 5, Funny

    Dear Professor,

    My final project for the semester is attached as a Word document. If you have any problems reading it, please let me know. Me and everyone else in your address book.

    Don't have to worry about grading it. By the time you read this, I will have used the root-kit to grade it myself.

    Nice porn, by the way! You dog! We'll make this our little secret.

    love,
    toodles

    1. Re:This aughta make FINALS more interesting... by Anonymous Coward · · Score: 2, Funny

      Dear Professor,

      My final project for the semester is attached as a Word document. If you have any problems reading it, please let me know. Me and everyone else in your address book.


      Dear surfcow,

      The syllabus clearly states that all electronically submitted assignments should be presented in PDF or other non-proprietry formats. Please resubmit your assignment.

      Love,
      Your physics professor
  14. Re:Bah, typical bullshit non-edited craptastic blu by munrom · · Score: 5, Funny

    Ah, license to ignore any unexpected memos for the next couple of days, excellent

  15. I advise the same thing by erroneus · · Score: 2, Funny

    Except that I have been saying that for years. MS Doc format is an untrustworthy format. It has been known to carry unexpected payloads in the past and there are alternatives which are known to be safer yielding similar if not identical results for most people. (And if someone thinks they actually NEED to have VBA in a word document, I'd have to suggest there's probably a better way to program your way out of the situation you find yourself in. I just haven't been able to think of a good reason to have programming code in a Word document and I haven't seen a good example either. Can anyone offer a reason good enough?

    ODT works well... hell, for that matter RTF works well enough for most people.

  16. Re:Blurb slightly-FUD by sharkey · · Score: 3, Funny

    But, I send you this file to ask you advice!

    --

    --
    "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
  17. Exercise caution... by flyingfsck · · Score: 5, Funny

    How is one supposed to exercise caution when opening a Word document? Do click on it slowly and deliberately, or do you click it carefully after giving the PC a pat on the head...

    --
    Excuse me, but please get off my Pennisetum Clandestinum, eh!
  18. I recommend... by LoverOfJoy · · Score: 1, Funny

    sticking with Word 97. It's apparently not affected by this.

    1. Re:I recommend... by Anpheus · · Score: 2, Funny

      I've noticed both Notepad and Wordpad are not vulnerable.

      I'll just stick with these inferior applications while boasting a smug sense of superiority.

      Ha-HA!

  19. we're all going to die.... by cheeseboy001 · · Score: 5, Funny

    Did anyone else read that as "Microsoft Ossues Zero-Day Attack Alert For World"?

  20. Sure... by Shawn+is+an+Asshole · · Score: 2, Funny

    That's why the Windows XP Security Guide is distributed a .doc...

    --
    "It ain't a war against drugs.it's a war against personal freedom" --Bill Hicks
  21. Re:what about OO.org? by Anonymous Coward · · Score: 1, Funny

    We tried, only to see that the documents were mangled and OO crashed often. Then someone told me it's always like that, so you should be fine.

  22. Next piece of helpful advice by DigitAl56K · · Score: 2, Funny

    "Do not start Windows, even when using trusted computing"

    I like Notepad better anyway.

  23. Re:Tell me about it... by jibjibjib · · Score: 2, Funny
    It's a pain to just write a simple letter.

    Would you like some help?

  24. Re:Article Summary is Flamebait by goombah99 · · Score: 3, Funny

    I'm sure there are Latex Trojans too. Used 'em myself.

    --
    Some drink at the fountain of knowledge. Others just gargle.
  25. If you stick with something long enough, by rssrss · · Score: 3, Funny

    you will be vindicated. I have stuck with Office 97, because I have never thought that any of the "improvements" that M$ has made in newer versions of Office were worth the price of a new program. It is now too old to be affected by the latest virus. Lord, this is sweet.

    --
    In the land of the blind, the one-eyed man is king.
  26. Re:ITS A TRAP! by johnw · · Score: 4, Funny
    Hey, our current products are insecure! So buy our latest one! It's better!

    Good marketing plan there.

    It's always worked in the past. Why change a winning formula?
  27. Re:Now might be a good time to try ... by Dekortage · · Score: 2, Funny

    I met a college student last year who writes all of her papers in Adobe Photoshop. She just sets up 300dpi pages and types all the text into text boxes. That way she could make pretty photographic backgrounds. And there are NO security issues!

    I didn't realize it then, but she is obviously a genius.

    --
    $nice = $webHosting + $domainNames + $sslCerts
  28. Re:No different than trusting a closed source vend by somersault · · Score: 2, Funny

    Maybe the method Word uses to render itself - when used on a certain font with the right combination of letters - infects your brain somehow. I guess it's working on the same principal as flash ads.

    --
    which is totally what she said
  29. Re:Now might be a good time to try ... by ConceptJunkie · · Score: 2, Funny

    Microsoft has made no promise about not doing evil, and they've shown it on a daily basis for 15 years.

    Of course, I would actually be happier if Microsoft would make a promise to "Do no stupid."

    --
    You are in a maze of twisty little passages, all alike.
  30. Its a good thing by Darkman,+Walkin+Dude · · Score: 3, Funny

    Microsoft is just taking the paperless office to the next level - the documentless office.

  31. OK, I can't be the only one to expect this... by Miss+Spider · · Score: 2, Funny

    From:
    To: All_Employees
    Subject: Corporate Security Alert
    Significance: High

    Microsoft has announced a security alert pertaining to MSWord - probably all versions. Microsoft recommends not opening any MSWord documents from anyone, until further notice. Please see attached for details.

    Thank you,
    IT Department

    [attachment - MSSecurityAlertDetails.doc - 1,253KB]