It all has to do with a specific kind of bug in certain Microsoft Office 2003 Applications. If an attacker wants to crash one of these apps, all they would have to do is design and deliver a specially crafted malformed file to the user. Upon opening the file, the app would crash. From a security standpoint, there have been a lot worse threats out there, but this can just be darn right annoying to deal with.
Microsoft Corp.’s Word 2003 and Excel 2003 can be crashed by attackers who feed the business applications malformed documents, Symantec Corp. reported Monday.
In separate alerts sent to subscribers of its DeepSight threat system, Symantec warned that the bugs — both discovered and disclosed by a Russian researcher with the moniker “sehato” — could be exploited by attackers to bring down the Office applications.
Microsoft did not immediately respond to an e-mail request for confirmation and comment.
“A remote attacker may exploit this vulnerability by presenting a malicious WMF file to a victim user,” said Symantec’s report on the Office 2003 flaw. “The issue is triggered when the application is used to insert the malicious file into a document.”[more]
Tags: Bugs

No Responses to “Office 2k3 Apps can Crash on Demand”
Please Wait
Leave a Reply
You must log in to post a comment.