Interview

Sai Infosystems- Setting High Standards...

Sai Infosystems- Setting High Standards...

In an exclusive interaction with ITVar News, Ki
Read More >

READ All

BitDefender Protects Against Zero-Day Microsoft Word Bug

Posted on July, Tuesday 22, 2008 By ITVN News Service

The vulnerability affects Word 2002 SP3, could be exploited by an attacker to "gain the same user rights as the local user", according to Microsoft.

Microsoft Corporation (I) Pvt. Ltd.
9th Floor, Tower A, DLF Cyber Greens
DLF Cyber Citi, Sector 25A
Gurgaon 122 002
INDIA

Phone: 1800 102 1100 (Toll free number accessible from Airtel land line and mobile
Phone: 1800 111 100 (Toll free number accessible from MTNL/BSNL land line)
Phone: +91 80 40103000

Fax: +91-124-4158888
You can also call at: 011 26292640 or send a fax at 011 42391186

The BitDefender Labs released a signature update to protect clients against the latest unpatched Word exploit. The vulnerability affects Word 2002 SP3, could be exploited by an attacker to "gain the same user rights as the local user", according to Microsoft. The exploit is already being used in the wild.

"The samples we retrieved were already being detected as malicious by BitDefender software, as the exploit was being used to drop a malicious executable file that we had already signed. As of this morning, we've also added detection for the exploit itsel

f, blocking this avenue of attack against our clients once and for all" explained Senior BitDefender AV Researcher Attila Balazs.


The dropped component is a backdoor detected by BitDefender as Backdoor.PoisonIvy.CV. Once installed, PoisonIvy grants complete control over the affected computer to an attacker.Malicious files containing the exploit are detected by BitDefender as Exploit.Word.MS-953635.A. The vulnerability itself is detailed in Microsoft Security Advisory 953635. An analysis of the PoisonIvy backdoor variant used in the attacks is ongoing and will be published on the BitDefender website as soon as possible.

Discuss this Story

 


 Add a Comment

Reload Image



"ITVAR News welcome comments that advance the story directly or with relevant information. We try to block comments that appear to be spam or use offensive language. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of IT VAR News or Techplus Media. We cannot be held responsible for error and authenticity of details associated with comments. IT VAR News does not endorse the products or its specifications."

 Comments

ss

Posted : July, Thursday 24, 2008

good.....itvarnews give a good news