Quantcast

Word Bug Can Permit Malicious Macros

Downloadable fix can swat bug that allows planting of potentially dangerous macros.

Sam Costello, IDG News Service

  • 0 Yes
  • 0 No

A flaw in several versions of Microsoft Word allows malicious macros to duck Word's security features and make possibly devastating changes to a PC.

The vulnerability affects Word 97, 2000, 2002, the Japanese version of Word 98, and Word for Macintosh 98 and 2001. Someone could exploit the vulnerability by performing what Microsoft calls "low-level editing" on a Word document to disguise the malicious macros and prevent Word's macro checker from detecting them, Microsoft officials acknowledge. A macro is a small script used to automate tasks, such as formatting.

Microsoft has posted a patch, along with a security bulletin, for this vulnerability. The flaw was discovered by Steven McLeod.

It is similar to another Word macro vulnerability discovered in May. Microsoft characterized that bug as "mild."

The earlier vulnerability occurred when a user opened an RTF file that referenced a template containing an embedded macro. The bug permitted the macro to run without warning the user, possibly making some changes to Word. It affected only Word 97 and later versions, and only certain RTF documents. Microsoft issued a patch for that bug as well.

Word Usually Watches Macros

Typically, Word alerts a user upon opening a document containing macros, and offers the option to run or disable them. Word also automatically checks for macros in any linked documents, including templates, within a document. But this bug disables that function, so a user wouldn't know that a malicious macro was present or had run. Such a macro could take any action that a user could, including changing or deleting files, contacting a Web site, disabling security settings, or even reformatting a hard drive, Microsoft says.

Users could access an affected Word document from a floppy disk, a Web page, or an attachment via e-mail.

Microsoft says this bug affects only Word, not other Office components. The Outlook Express security update, which is included with Word 2002, is protected from e-mail worms and would also protect users from a Word document with a malicious macro.

Macros have long been the province of annoying, but usually not terribly destructive, viruses.

  • Recommend this story?
  • 0 Yes
    0 No

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

Featured APC Accessories For Your System
10% Off Entire Cart at Online Store

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

PC World's Marketplace