laurierobey: (NW--Pfui!!)
[personal profile] laurierobey
http://www.eweek.com/article2/0,1895,1966730,00.asp?kc=ewnws052406dtx1k0000599

Exerpts from the article on how to counter the vulnerability, for now:

Use Microsoft Word in safe mode to protect against targeted zero-day attacks.

That's the advice from Microsoft's security response team to counter known attacks against a serious code execution vulnerability in the widely used word processing program.

Microsoft is also offering the following guidelines for Office documents in safe mode:

Do not open Word files that are embedded in other applications, such as Excel, PowerPoint and others.

Even after applying the workarounds, do not open Word files directly from any mail clients—for example, Outlook or Hotmail—by double-clicking them. Save your Word document to a disk or onto your desktop and use the "Word Safe Mode" Shortcut.

Do not open ".doc" files from a Web site via Internet Explorer or any other browser.

If you do not see "Safe Mode" in Word title bar, you are not running Word in safe mode. Do not attempt to open any Word files as you may be vulnerable to the malicious ".doc" files.

Use Word Viewer 2003 to open and view files. The free Word Viewer 2003 does not contain the vulnerable code and is not susceptible to this attack.
In the attacks seen against select targets, two e-mail subject lines have been used. One is simply the word "Notice" and the other reads: "RE Plan for final agreement."

Two e-mail ".doc" attachments have been reported: "NO.060517.doc.doc," and "PLANNINGREPORT5-16-2006.doc."


~~~~~~~~~~~~~~~~~~~~~~~~~

Must be a pretty big, bad vulnerability if they're telling users to go through all this.

Date: 2006-05-24 06:58 pm (UTC)
From: [identity profile] fferret.livejournal.com
Ya notice what I've not seen in any of the trades? Or any other coverage of the exploit? How the frack do you start Word in safe mode? Do you know?

Date: 2006-05-24 07:34 pm (UTC)
From: [identity profile] laurie-robey.livejournal.com
MS lists the directions here:

http://www.microsoft.com/technet/security/advisory/919637.mspx

under the "workarounds" section.

Basically don't use Word as your Outlook mail editor and add "/safe" onto your winword.exe command line.

I've never heard of Word's "safemode" before now.

Date: 2006-05-24 07:42 pm (UTC)
From: [identity profile] fferret.livejournal.com
(*snorts*) Frankly, if Microsoft went to all the trouble of indoctrinating their users in how to use the GUI, how do they expect them to actually change a command string? I can do it, but I'm older than dirt, and have been in IT for close to 30 years now. I can still recall DOS commands!

Profile

laurierobey: (Default)
laurierobey

January 2013

S M T W T F S
  1 2 34 5
6 789101112
13141516171819
20212223242526
2728293031  

Most Popular Tags

Style Credit

  • Style: Caturday - Orange Tabby for Heads Up by momijizuakmori

Expand Cut Tags

No cut tags
Page generated Feb. 4th, 2026 07:24 am
Powered by Dreamwidth Studios