Microsoft
Five unpatched Office vulnerabilities are leading to a 'malware storm'

Zero-day Office attacks leave experts worried

'Is every day zero day at Microsoft?' asks researcher

Written by Shaun Nichols in California

Security experts have voiced grave concerns for the safety of users in the wake of a string of active exploits for Microsoft Office.

Cory Nachreiner, a network security analyst at WatchGuard Technologies, said that the crop of five unpatched Office vulnerabilities is leading to a "malware storm" and asked whether "every day is zero day" for Microsoft Office. 

"Microsoft had better get in gear and at least laminate its paper bag so we can weather this malware storm," the analyst said.

Nachreiner's comments come after the disclosure of a fifth new vulnerability in Microsoft Office.  

The latest vulnerability affects Excel, and allows attackers to remotely execute code on a compromised system. The four previous vulnerabilities all targeted Microsoft Word.

Attackers have been exploiting the newly-discovered vulnerabilities in recent weeks. The Excel vulnerability has been used by attackers to install working malware applications. Attacks targeting unpatched vulnerabilities in Word also continue to circulate.  

Microsoft and third-party security vendors have warned users not to open any unsolicited or otherwise suspicious file attachments.

Nachreiner warned that the consequences could be dire if Microsoft is unable to publish fixes for all of the Office vulnerabilities by next Tuesday's monthly security update.

"With a bunch of zero-day vulnerabilities actively floating around the internet, I hope Microsoft fixes these Office issues soon, preferably this upcoming patch day," said Nachreiner.

"If it does not, many innocent Office users will get blown away by the ongoing malware storm."

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

 

A week in security: Microsoft details Patch Tuesday

V3.co.uk rounds up the week's top security stories 10 Jul 2010

2010 smashes vulnerability records

Busiest year yet for researchers and patchers, says IBM's X-Force 25 Aug 2010

Zero-day Microsoft flaw already being exploited

Vulnerability published by Google researcher could allow remote code execution 16 Jun 2010

related white papers

today's top stories

Amazon Kindle 3 e-book reader review

Amazon trims the size and price of its newest Kindle, and adds a bargain Wi-Fi-only model 02 Sep 2010

RBS to cut 1,000 IT roles

Royal Bank of Scotland has announced it will cut 3,500 jobs, 1,000 of which are in IT support 02 Sep 2010

Apple overhauls iPod Shuffle, Nano and Touch

New models come with iTunes update and social networking tool 02 Sep 2010

Scottish school shifts wholly to the iPad

Head of computing and IT at Cedars School gives the rationale behind his decision 01 Sep 2010

Salford's MediaCity pushes technology boundaries

In preparation for 3D, ultra HD and a tapeless workflow 02 Sep 2010

Advertisement

Power and cooling management for the data centre
The principles for achieving power and cooling capacity management in the modern data centre

The value of virtual infrastructures to business continuity
This IDC paper examines the role of server and storage virtualisation in enabling application and data continuity at a lower overall cost

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

picture of a TV studioAnalysis

Salford's MediaCity pushes technology boundaries

In preparation for 3D, ultra HD and a tapeless workflow 02 Sep 2010

Second Life avatarAnalysis

What are the business benefits of virtual worlds?

Experts cite collaboration and brainstorming, recruitment and training 26 Aug 2010

Primary Navigation