Microsoft has issued a
warning for a new unpatched vulnerability in its Word text editor that attackers are actively exploiting.
Attackers can exploit the vulnerability by luring their victims into opening a specially crafted Word document. Upon infection, the attacker can take over control of the victim's system.
The flaw affects Word 2000 and Word XP. Users are urged not to open any documents that originated from unknown sources.
The attack comes one day after Microsoft issued its monthly set of security patches, which contained three updates for the Office productivity suites.
Word and Excel vulnerabilities are a popular with attackers that target enterprise systems. In the past months numerous attacks have popped up where criminals send out spam email messages with a specially crafted Word or Excel document to a few key staff members inside one or a few organisations. The attacks allow them to gain access to trade secrets or confidential customer information.
The attacks prey on business user's familiarity with Word and Excel applications. Launching small scale attacks also limits the chances that a piece of malware gets detected by security software, allowing the criminals to launch several raids before the security hole that they are exploiting gets plugged.