TechCountry



If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.



Notices

Security Anti virus, Firewalls, Exploits and other security concerns

Reply
Old 02-26-2008, 12:12 AM   #1 (permalink)
Administrator
 
Kevin's Avatar
 
Join Date: Feb 2008
Location: LA Cali
Posts: 1,138
Thanks: 3
Thanked 4 Times in 4 Posts
Rep Power: 30 Kevin is on a distinguished road
Send a message via MSN to Kevin
Exclamation Warning of word 0 day exploit

MDropper Trojan - Exploits Zero Day vulnerability in MS Word http://vil.mcafeesecurity.com/vil/content/v_139539.htm
http://www.sarc.com/avcenter/venc/da...dropper.h.html
http://secunia.com/virus_information/29277/mdropper.h/
http://securityresponse.symantec.com...or.ginwui.html

Trojan.Mdropper.H is a Trojan horse that downloads other risks onto the compromised computer. This Trojan exploits a 0 day Microsoft Word vulnerability to drop Backdoor.Ginwui.


TITLE:
Microsoft Word Unspecified Code Execution Vulnerability

SECUNIA ADVISORY ID:
SA20153

VERIFY ADVISORY:
http://secunia.com/advisories/20153/

CRITICAL:
Extremely critical

IMPACT:
System access

WHERE:
>From remote

SOFTWARE:
Microsoft Office 2003 Professional Edition http://secunia.com/product/2276/ Microsoft Office 2003 Small Business Edition http://secunia.com/product/2277/ Microsoft Office 2003 Standard Edition http://secunia.com/product/2275/ Microsoft Office 2003 Student and Teacher Edition http://secunia.com/product/2278/ Microsoft Office XP http://secunia.com/product/23/ Microsoft Word 2002 http://secunia.com/product/2150/ Microsoft Word 2003 http://secunia.com/product/4908/

DESCRIPTION:
A vulnerability has been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an unspecified error. This can be exploited to execute arbitrary code.

NOTE: This vulnerability is being actively exploited.

The vulnerability has been reported in Microsoft Word 2002 and Microsoft Word 2003.

SOLUTION:
Do not open untrusted Office documents.

PROVIDED AND/OR DISCOVERED BY:
This vulnerability has been discovered in the wild as a "Zero-day"
while investigating a system compromise.

OTHER REFERENCES:
SANS:
http://isc.sans.org/diary.php?storyid=1345
__________________
-Webmaster aka Kevin-J View my Blog
Kevin is offline   Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -5. The time now is 03:52 PM. Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0 TechCountry - 2008



Inactive Reminders By Icora Web Design