Macintosh Crafted Word Document Carries MalwareBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard - New Version 9 Out Now - Dld 30-day trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/7 19:22:16
2009/11/7 19:22:16
2009/11/7 19:22:16
2009/11/7 15:40:03
Our Partners
Downloads
Adware - Spyware : Macintosh Crafted Word Document Carries Malware
Posted by Max on 2007/10/23 12:27:33 (1328 reads)
Adware - Spyware

Symantec researchers have discovered a special crafted Word document which deploys malware on the infected Macintosh computers. Yes, the file was forged using the Macintosh version of Word and it's designed to exploit a recent Word security hole fixed by Microsoft on Tuesday.

"After some investigation we determined that the document had actually been created using Word for Macintosh," Symantec noted on their Security Response blog. A peek at the document header revealed someone had created it on a Mac, instead of a PC.

If successful, this attack would drop a trio of malicious files onto a machine. A couple of Trojans and a rootkit arriving via the Word attack vector could turn a PC into another rooted bot on the Internet.

It seems that the trend for exploiting vulnerabilities around the same time as Patch Tuesday continues. Microsoft themselves confirm in their advisory that they have seen this issue exploited in the wild. However, in our experience the exploitation of such vulnerabilities tends to be very targeted in nature.

The good news is that the default configuration in Microsoft Office 2007 and Office 2003, Service Pack 3 will not allow you to open some older Office file formats, including Office for Macintosh documents (see MS KB922850 for further details). We're continuing to investigate the behavior of the exploit on other Office versions said Symantec.

Symantec Antivirus products will detect the malicious document as Trojan.Mdropper.Z. The dropped files are detected as Trojan.Dropper, Backdoor.Trojan and Hacktool.Rootkit.




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.