This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Olympic spam carries malicious code - 0-day Word

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://preview.tinyurl.com/383so5
February 25, 2008 (SCMagazineUS.com) - "A legitimate attachment containing information about security for the upcoming Beijing Summer Games is also masking a trojan, researchers at MessageLabs said. The documents, which appear to come from Olympic mail servers, but include embedded malware, are so relevant to the recipient that researchers have noticed many victims are forwarding the malicious messages on to other Olympic committee members. "These are otherwise perfectly valid documents,” Maksym Shipka, senior architect at MessageLabs, told SCMagazineUS.com today. “It's real information. It's a continuation of actual email conversations. Yet the document is bad.” Opening the attachment activates a zero-day exploit in Microsoft Word, according to MessageLabs. The document silently extracts and runs the malicious code on the end-user's computer…"

:ph34r:
FYI…

- http://www.symantec.com/avcenter/threatcon/learnabout.html
Feb 28, 2008 - "…We have completed research into the reports of spam emails containing malicious Microsoft Word document attachments. The original reports described the Word document email attachments as zero-day exploits. Further research into the threat has now revealed that the malicious document is exploiting the Microsoft Word Array Remote Code Execution Vulnerability (BID 23804*). Administrators are advised to:
- Ensure that the security updates from MS07-024 are installed on all systems that have vulnerable versions of Microsoft Office installed.
- Ensure that antivirus definitions are up to date. Symantec AntiVirus detects this threat as Trojan.Mdropper. Microsoft Security Bulletin MS07-024 Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (934232)
( http://www.microsoft.com/technet/security/…n/MS07-024.mspx )
Microsoft Word Array Remote Code Execution Vulnerability…"
* http://www.securityfocus.com/bid/23804/solution

.