Microsoft Office 2003 Apps Hit with New Crash Bugs
Microsoft Office apps can be crashed by attackers who feed the business applications malformed documents, Symantec reports.
Gregg Keizer, Computerworld
Microsoft Corp.'s Word 2003 and Excel 2003 can be crashed by attackers who feed the business applications malformed documents, Symantec Corp. reported Monday.
In separate alerts sent to subscribers of its DeepSight threat system, Symantec warned that the bugs -- both discovered and disclosed by a Russian researcher with the moniker "sehato" -- could be exploited by attackers to bring down the Office applications.
Microsoft did not immediately respond to an e-mail request for confirmation and comment.
"A remote attacker may exploit this vulnerability by presenting a malicious WMF file to a victim user," said Symantec's report on the Office 2003 flaw. "The issue is triggered when the application is used to insert the malicious file into a document."
Specially crafted WMF (Windows Metafile) image files were the root of a major attack in late 2005 and early 2006 that was launched from hundreds of malicious Web sites and compromised thousands of PCs. This bug seems to be different from the 2005/2006 vulnerability.
The Excel flaw can be leveraged by a malformed spreadsheet file rather than a WMF image, Symantec added.
Attacks using either vulnerability require users to download malicious files from a Web site or open them when they arrive as e-mailed file attachments.
Also at risk, said Symantec, is XP's and Server 2003's Windows Explorer, the operating system's file interface. Explorer will crash when attempting to open a malformed WMF image, said the Cupertino, Calif.-based company. Sehato divulged this third bug as well.
Problems with Microsoft's Office software have been endemic since early 2006, and there are no signs that hackers and researchers have emptied its well of vulnerabilities. During 2006, for example, Microsoft issued 13 security updates for Office 2000 and 11 for Office 2003. In the first two months of 2007, it released four bulletins for Office 2000 and six for Office 2003.
And last week, eEye Digital Security announced that its researchers had uncovered the first known Office 2007 flaw.

For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
PCW Download Guide
Laptop Showcase
Related Office Articles
- Xcelsius: How to Ruin a Great Application A really, really, really cool application gets sidelined in a swirl and flurry of filthy lucre.
- File Storage and Viewing Apps for IPhone Storing media like photos, music, and video on your iPhone is a snap: after all that's what the device was designed for. But...
- Office 2008 Survival Guide If you've recently upgraded to Microsoft Office 2008, you may like the productivity suite's new features, but you may also...
- Microsoft Fights Piracy with Price Drop--in Kenya Microsoft East Africa has reduced the price of its Office suite software while complaining of rampant software piracy.
- E-Mail Hoaxes, XP Buyers, and Symantec's Buy Readers discuss crazy hoaxes, why XP is still popular, and what Symantec's purchase of PC Tools means.
Best Prices on Security Software
Norton Internet Security 2008Price: $19.15
Internet Security 2008 - 3-User (Full Product, PC)Price: $12.99
Internet Security Suite 2008 - 3-UserPrice: $18.95
Norton 360 2.0 ( PC)Price: $33.99
Internet Security 7.0 - 3-UsersPrice: $17.95
Internet Security Suite 2008 w/Site Advisor - 3-UserPrice: $10.00
- CDW Virtualization Center What is Virtualization and how can it help you save money? Click here to find out.
- Asus Laptop Showcase Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more...
- HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...








"Microsoft Office 2003 Apps Hit with New Crash Bugs" Comments