MS Word Zero-Day Exploit Found 396
subbers writes "A zero-day flaw in Microsoft Word program is being used in an active exploit by sophisticated hackers in China and Taiwan, according to warnings from anti-virus researchers. The exploit arrives as an ordinary Microsoft Word document attachment to an e-mail and drops a backdoor with rootkit features when the document is opened and the previously unknown vulnerability is triggered. From the article: 'The e-mail was written to look like an internal e-mail, including signature. It was addressed by name to the intended victim and not detected by the anti-virus software.'"
At least it's not open source (Score:5, Funny)
In related news (Score:5, Funny)
real damage? (Score:5, Funny)
Yeah, but can they do any real damage? : p
Ahh Microsoft (Score:4, Funny)
Patch available (Score:3, Funny)
Re:is Microsoft this fragile? (Score:1, Funny)
If someone figures out how to put a root kit in a (Porn)MPEG file, the internet would be fucking gone!
Only a taste... (Score:5, Funny)
Re:This is nonsense! (Score:3, Funny)
When some other OS with some other standard office suite becomes the de facto standard for business AND for home users, we'll see the same sort of security breaches for that particular combination or software. It hasn't been done yet on because there are twenty (or more) times as many Windows machines, and Windows has a larger percentage of careless users.
When Joe Six Pack switches to Linux/Unix/Mac/whatever and MS is the underdog, suddenly they'll be the secure ones.
Incidentally, it's not trolling to point out that I haven't seen a virus since early 2000, and that was because I hated updating W2K on dialup and put it off.
Re:When do we see a patch? (Score:3, Funny)
Re:doesn't affect me (Score:3, Funny)
Re:At least it's not open source (Score:3, Funny)
Yes, you never know whether an exploit is going to work on an OSS platform.
Now this is what I call an "Open Document Format"! (Score:2, Funny)
It is Open, as in open for hackers to drop root kits on your system.
As in grab you ankles open.
It is also Accessable, as other people now have access to your system.
Why does a document need to have the ability to contain code and execute code on your system?
I'd be happy with just formatting features and losing all "fancy garbage" that allows these holes to exist.
Name Change? (Score:5, Funny)