Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Trojan rides in on unpatched Office flaw
Cnet News ^ | 09/30/2005 | Joris Evers

Posted on 10/01/2005 6:49:31 AM PDT by Panerai

A new Trojan horse exploits an unpatched flaw in Microsoft Office and could let an attacker commandeer vulnerable computers, security experts have warned.

The malicious code takes advantage of a flaw in Microsoft's Jet Database Engine, a lightweight database used in the company's Office productivity software. The security hole was reported to Microsoft in April, but the company has yet to provide a fix for the problem.

"Microsoft is aware that a Trojan recently released into the wild may be exploiting a publicly reported vulnerability in Microsoft Office," a company representative said in a statement sent via e-mail on Friday. The software maker is investigating the issue and will take "appropriate action," the representative said.

The Trojan horse arrives in the guise of a Microsoft Access file, security software maker Symantec said in an advisory. When run on a vulnerable system, it would give a remote attacker full access to a compromised computer, Symantec said. The company calls the pest "Backdoor.Hesive" and notes that it is not widespread.

Although exploits had already been released in April when HexView publicly reported the flaw, the Trojan is believed to be the first actual threat to take advantage of the security hole. Security monitoring firm Secunia rates the issue "highly critical," one notch below its most serious rating.

(Excerpt) Read more at beta.news.com.com ...


TOPICS: Technical
KEYWORDS: microsoft; ms; office; wasteoftime
Navigation: use the links below to view more comments.
first previous 1-2021-4041-42 last
To: Petronski

Or laugh.


41 posted on 10/01/2005 9:13:28 PM PDT by Golden Eagle
[ Post Reply | Private Reply | To 40 | View Replies]

To: ikka
The old "more users thus more attacks" canard is easily demonstrated to be false, since the Apache web server (which runs on Unix systems) has much more market share and runs on many more machines; yet MSFT's IIS web server is far and away compromised more often.

Wrong, try comparing apples with apples. Compare Apache to IIS6. You're in for a surprise.
42 posted on 10/02/2005 8:11:18 PM PDT by Bush2000 (Linux -- You Get What You Pay For ... (tm)
[ Post Reply | Private Reply | To 12 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-42 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson