Re: Alert: Microsoft Security Bulletin - MS03-036
From: James C. Slora, Jr. (Jim.Slora_at_PHRA.COM)
Date: 09/03/03
- Previous message: Marc Maiffret: "EEYE: VBE Document Property Buffer Overflow"
- Maybe in reply to: Russ: "Alert: Microsoft Security Bulletin - MS03-036"
- Next in thread: Gary Flynn: "Re: Alert: Microsoft Security Bulletin - MS03-036"
- Reply: Gary Flynn: "Re: Alert: Microsoft Security Bulletin - MS03-036"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 3 Sep 2003 16:09:24 -0400 To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Criticality of this is horribly underrated by Microsoft.
This is critically important for all Windows MS Office users - "the user must open the attachment" is no protection because most users open attachments to see what they are.
If the infected Word Perfect document is given a .DOC extension, Word will be invoked directly when the user double-clicks the attachment. Word will automatically recognize and convert the document, and run the hostile code with no further opportunity for the user to stop the virus.
The vulnerability could also be exploited through a web page, and the user would get no chance to say "No" if ActiveX is enabled.
-ooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Whatever Happened to Octopus?
LEGATO RepliStor, formerly known as Octopus, delivers breakthrough
replication performance that's 5X faster than the competition in an
independent head-to-head test. Learn how RepliStor uses patented,
asynchronous, real-time replication, to deliver disaster recovery, data
distribution and consolidated backups. It is the first replication solution
to achieve Windows 2003 certification. Get the performance report now.
http://portal1.legato.com/products/replistor/upgrade.cfm
-ooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
- Previous message: Marc Maiffret: "EEYE: VBE Document Property Buffer Overflow"
- Maybe in reply to: Russ: "Alert: Microsoft Security Bulletin - MS03-036"
- Next in thread: Gary Flynn: "Re: Alert: Microsoft Security Bulletin - MS03-036"
- Reply: Gary Flynn: "Re: Alert: Microsoft Security Bulletin - MS03-036"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|