Microsoft Issues Zero-Day Attack Alert For Word
0xbl00d writes "Eweek.com is reporting a new Microsoft Word zero-day attack underway. Microsoft issued a security advisory to acknowledge the unpatched flaw, which affects Microsoft Word 2000, Microsoft Word 2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac and Microsoft Word 2004 v. X for Mac. The Microsoft Works 2004, 2005 and 2006 suites are also affected because they include Microsoft Word. Simply opening a word document will launch the exploit. There are no pre-patch workarounds or anti-virus signatures available. Microsoft suggests that users 'not open or save Word files,' even from trusted sources."
That the business world just stop for a few minutes(days, weeks) while they fix this.
If I can't even open my friends' documents then what am I - as a manager to do?
Oh, wait - I don't do anything anyway and my life revolves around Excel.
Nevermind.
The Kai's Semi-Updated Website Thingy
So let me get this straight... For the time being the only safe Word files are new files that other people don't need to open?
But hey, you saved a ton of money on retraining costs.
Maybe not
http://docs.google.com/
Could the problem be avoided by opening the any .doc files with OO.org? i'm assuming that the exploit will only work if the file is actually opened with word, so it would stand to reason that opening it with some other application would be safe. can anyone tell me why i'm wrong?
my pet machine
Good general advice, really. They should put that on the Office packaging, like on a packet of cigarettes.
ant
In the meantime, download and use OpenOffice
2cv
Comment removed based on user account deletion
That is nothing more than standard precautions that one should take anyway. If you aren't expecting an attachment, don't open it. If you are expecting it, and it is from a trusted source, go ahead.
Really? I get documents that I'm not expecting all the time. I never have any fears opening Latex documents from anybody. You Microsoft folks sure have funny security.
And thus begins the torrent of Microsoft mocking posts. Get your mod-points out and set them to +5 Funny because the laughs are only just beginning. *sigh*
Zero day: At the time the details of the exploit are published (or the patch is released), there already is an active exploit being circulated. I guess if you don't know exactly when the exploit was released it's a technically "less than or equal to zero-day" exploit, but that doesn't sound as sexy.
It means that there is a working exploit out there in the wild, which is using a vulnerability that was previously unknown to the security community / the software maker. That is, there was zero days warning.
If J.K.R wrote Windows: Puteulanus fenestra mortalis!
Yet ANOTHER feature Word has that OpenOffice doesn't. :(
Yeah, they taught me in school that latex was a good way to guard from viruses.
Dear Professor,
My final project for the semester is attached as a Word document. If you have any problems reading it, please let me know. Me and everyone else in your address book.
Don't have to worry about grading it. By the time you read this, I will have used the root-kit to grade it myself.
Nice porn, by the way! You dog! We'll make this our little secret.
love,
toodles
Ah, license to ignore any unexpected memos for the next couple of days, excellent
How is one supposed to exercise caution when opening a Word document? Do click on it slowly and deliberately, or do you click it carefully after giving the PC a pat on the head...
Excuse me, but please get off my Pennisetum Clandestinum, eh!
Did anyone else read that as "Microsoft Ossues Zero-Day Attack Alert For World"?
It's always worked in the past. Why change a winning formula?