- http://www.us-cert.gov/cas/techalerts/TA06-139A.html
May 19, 2006
Systems Affected
* Microsoft Word 2003
* Microsoft Word XP (2002) …
- http://www.kb.cert.org/vuls/id/446012
Overview
A buffer overflow in Microsoft Word could allow a remote attacker to execute arbitrary code with the privileges of the user running Word.
I. Description
Microsoft Word contains a buffer overflow vulnerability. Opening a specially crafted Word document (including documents hosted on web sites or delivererd as email attachments) could trigger the vulnerability.
II. Impact
By convincing a user to open a specially crafted Word document, an attacker could execute arbitrary code with the privileges of the user running Word. If the user is logged in with administrative privileges, the attacker could take complete control of a vulnerable system.
III. Solution
Do not open untrusted Word documents. Do not open unfamiliar or unexpected email attachments, including Word or other Office documents, even if sent by a known and trusted source. Please see Cyber Security Tip ST04-010* for more information…"
- http://www.pcworld.com/news/article/0,aid,125798,00.asp#
May 19, 2006
"Microsoft Word users should be extra careful about the files they download because hackers are exploiting an unpatched vulnerability in the popular word-processing software. Security vendor McAfee warned users Thursday of a new Trojan horse program, called BackDoor-CKB!cfaae1e6, that secretly installs software on a computer. For the program to work, however, hackers must first trick users into opening a malicious Word document. Once that has been done, the results can be nasty. Installed, the malware lets hackers "execute any external commands, download additional Trojans, capture desktop screen shots, monitor and record keystrokes or passwords," McAfee said*… SANS has published a number of tips on how to avoid this type of attack**… Microsoft is testing a fix for the Word vulnerability and expects to include it as part of its next round of monthly security patches, which are scheduled to be released on June 13***."
- http://blogs.technet.com/msrc/archive/2006/05/20/429612.aspx
Saturday, May 20, 2006 9:03 PM
"…The attack we’ve seen is email based. The emails tend to arrive in groups, they often have fake domains that are similar to real domains of the targets, but the targets are valid email addresses. Currently two of the subject lines we have seen are:
Notice
RE Plan for final agreement …"
—————————————-
Also:
- http://securityresponse.symantec.com/avcen…oor.ginwui.html
Last Updated on: May 19, 2006
"…Creates the following files:
* %System%\Winguis.dll
* %System%\drivers\IsPubDRV.sys
* %System%\drivers\RVdPort.sys
* %System%\drivers\DetPort.sys …"
The information about vulnerable exploits differs a little between the two advisories. Microsoft says the vulnerability only affects Word 2002/XP and Word 2003 and that Word 2000 is not vulnerable. The Microsoft advisory contains information on workarounds including not using Word as the default mail editor in Outlook and running Word in 'Safe Mode' to disable the functionality that is affected by the vulnerability and exploit.
Eeye says that the vulnerability affects Word 2000 as well. The Eeye advisory mentions that they believe there are two variants of this exploit. Thus, it may be that the first variant only affects Word 2002/XP and 2003 and the second variant affects all three versions."
Sourcefire VRT MS-WORD 0DAY recommendations, Rules and tool Advisory
- http://isc.sans.org/diary.php?storyid=1363
Last Updated: 2006-05-26 22:27:22 UTC
"…Sourcefire VRT has an Advisory* that contains MS-WORD 0DAY recommendations, Rules, and the "SOURCEFIRE MS-WORD 0DAY, checker v0.1 DocCheck tool download…"
Microsoft Security Advisory (919637)
Vulnerability in Word Could Allow Remote Code Execution
- http://www.microsoft.com/technet/security/…ory/919637.mspx
Updated: June 2, 2006
…Revisions:
• V1.1 (June 2, 2006): Advisory revised to update the “Frequently Asked Questions” section and provide additional clarity around “Step 2 Append /safe to the WINWORD.EXE command line” for “Enterprise Customers using group policy” section under “Always use Microsoft Word in Safe Mode”.