Microsoft warns of security bug exploiting 'preview email' to hack PC

Image
ANI Washington
Last Updated : Mar 26 2014 | 3:40 PM IST

Microsoft has reportedly warned that previewing emails before hitting send could allow hackers gain control of a user's PC.

The software maker said that cybercriminals were actively exploiting a newly discovered Microsoft Word bug that could be exploited to gain remote access of a system.

According to PC World, the attack is delivered using booby-trapped Rich Text (RTF) files and accessing or previewing a bugged file with Word grants the attacker the same rights as the current user.

And the worst part is that Word is the default document viewer in Outlook 2007, 2010 and 2013.

Microsoft is only aware of the limited, targeted attacks against Word 2010, but the bug affects Word 2013, Word 2013 RT, Word 2007, Word 2003, Microsoft Office for Mac 2011, and related programs like Word Compatibility Viewer and Word Automation Services on Microsoft SharePoint Server, the report said.

Although Microsoft has issued a Fix It to neutralize the exploit by going the nuclear route and barring all RTFs, but since RTF formats are popular than Microsoft's .Doc formats, users could configure Outlook settings to avoid any potential hacks.

Users should try to stay away from RTF files, but if there is no other option, they could scan it with security software first.

Microsoft said that running its Enhanced Mitigation Experience Toolkit (EMET) could also protect against the exploit.

The report said that since the exploit also involves Word 2003, and Office 2003 is going end-of-life on April 8 with Windows XP, it means no more security patches for such issues and users must adopt the updated versions.

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Mar 26 2014 | 3:25 PM IST

Next Story