Backdoor Trojan targets Microsoft Access
Zero day vuln gives hackers open access
Posted in Software & Security, 3rd October 2005 14:03 GMT
Free whitepaper – Managing desktop software for fun and profit
Virus writers have created a Trojan which uses an unpatched vulnerability in Microsoft Office to take over Windows PCs. The Hesive Trojan can be disguised as a Microsoft Access file. Once opened in Access, infected .mdb files take advantage of a five-month old buffer overflow flaw in Microsoft's Jet Database Engine software to seize control of vulnerable machines.
Incidents of the Trojan are rare but the creation of the first malware to target this unfixed security bug shows VXers are broadening the range of their attacks beyond targeting IE and Windows operating systems flaw to begin looking at Office applications. In this way skills associated more typically with targeted hacking attacks are being rolled into malware creation.
Microsoft is yet to fix the Database Engine glitch but the creation of malware specifically targeting a security bug with a core component of Office ought to speed the creation of a fix. ®
Free whitepaper – Managing desktop software for fun and profit
Analyst Keynote: The Register Agile Data Center Summit
Dell PowerEdge R710 solution with VMware ESX vs. Dell PowerEdge 2850 solution
Seven ways to lower storage costs

Sign up, sign up for The Register IT security newsletter
Microsoft's Windows 7 price gamble - and why it's flawed
Managing Desktop Software for fun and profit
Intel's flash new SSDs hit by bugs