FYI…

- http://www.avertlabs.com/research/blog/?p=189
January 31, 2007 ~ "…a flurry of four Microsoft-related zero-day exploits.
The first three of these flaws affect Microsoft Visual Studio:
http://vil.nai.com/vil/content/v_vul27819.htm
http://vil.nai.com/vil/content/v_vul27827.htm
http://vil.nai.com/vil/content/v_vul27831.htm
(… Vendor Status
Unacknowledged …)
…The fourth flaws affects Microsoft Word:
- Microsoft Word 0-Day Vulnerability IV
http://vil.nai.com/vil/content/v_vul27845.htm
All four flaws would allow a remote attacker to execute arbitrary code on a vulnerable machine. For an attack to occur in all four cases, user interaction is required; e.g., a user would have to visit a Web site that hosts a malicious file or open a malicious file locally. With Microsoft’s next Patch Tuesday falling on February 13, these flaws will remain un-patched for at least two more weeks…"

(Add: http://isc.sans.org/diary.html?storyid=2157 …to the list of "Known unpatched active exploits".)

- http://isc.sans.org/diary.html?storyid=1940
Last Updated: 2007-02-03 12:39:00 UTC …(Version: 17)

:ph34r: