Detects 'long-standing' security vulnerabilities in Microsoft Office
Security firm Bkav on July 22 has warned that a Microsoft Office vulnerability has been quietly exploited since 2009.
A vulnerability in Office 2003 has just been discovered
According to experts, during nearly 4 years, many users in Vietnam may have become victims without knowing it, even though they regularly update the manufacturer's patches.
Specifically, the MS13-051 vulnerability exists in the PNG image processing mechanism of Microsoft Office 2003. To exploit, hackers create a Word text file that has installed malicious code, with compelling content to lure users. open. As long as the file is opened, the virus will immediately be activated, creating a backdoor for hackers to take control of the remote system.
This is a serious flaw, especially experts say the exploit code MS13-051 has silently appeared four years ago on the Internet. This means that many users can be tracked, stolen, changed data . without knowing it.
Bkav recommends, users should upgrade to a higher version of Microsoft Office 2003. In addition, to prevent malicious infection from text files, users need to install capable antivirus software. anti-spyware and anti-spyware.
You should read it
- Hackers are using new Microsoft Office vulnerabilities to distribute malware
- Let Microsoft Office become more perfect
- The unpatched Microsoft Word DDE vulnerability is exploited in a massive malware attack
- Link Download Microsoft Office 2019
- Hacker exploited three vulnerabilities in Microsoft Office to spread Zyklon malware
- Microsoft Office iOS app has an important update, supports downloading PDF files for offline use
- 10 great tools of Microsoft Word
- 4 things to expect in Microsoft Office 15
May be interested
- Microsoft fixes 8 critical vulnerabilitieson june 13, microsoft issued eight security patches for vulnerabilities in windows operating systems, internet explorer, windows media player and office software.
- Microsoft discovered a critical vulnerability on macOSmicrosoft has just discovered a critical vulnerability in apple's macos. a new vulnerability called shrootless on macos discovered by microsoft is very serious.
- Microsoft expert discovered a series of serious code execution errors in IoT, OT devicesmicrosoft security researchers announced that they discovered more than two dozen serious remote code execution (rce) vulnerabilities related to internet of things (iot) and operational technology (ot) devices being used. relatively popular use today.
- 70% of Microsoft security vulnerabilities stem from memory errorsat the bluehat security conference in israel discussing security over the weekend, a microsoft engineer revealed that over the past 12 years the number of patches microsoft has released to fix security-related errors memory accounts for about 70%.
- Detects many security vulnerabilities in Lenovo server infrastructurethere are a total of 9 different security holes found in lenovo's server infrastructure.
- 5 common errors in managing security vulnerabilitiesin the eyes of some people the issue of managing vulnerabilities is considered one of the intensive security management activities. there are others who think this is just a necessary process that microsoft has to make
- Microsoft patched a series of serious bugs for IE and Office next Tuesdayusers of microsoft products are familiar with patch tuesday - the second third day of the month - often used by microsoft to release patches for their products. tuesday march 12 will be a very important patch tuesday.
- Microsoft introduced a tool to fix security holes in IE 9 and 10microsoft has released an official security warning regarding zero-day vulnerabilities in ie10 last week and said ie 9 is also vulnerable.
- IBM developed a new technology to patch security holestop security researchers at ibm have recently developed a new technique to etch almost entirely the impact of security vulnerabilities before they are actually found.
- New service Microsoft 365 encapsulates the OS, Office and Microsoft security toolsat the microsoft inspire conference held on july 10, microsoft announced a new service called microsoft 365, which will include three of its earlier separate services, office 365, windows 10 and enterprise mobility + security.