Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

5/19/2006
08:15 AM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Targeted Word Trojan Found

A Trojan that exploits a zero-day vulnerability has been found in the wild. Experts say not to be alarmed

A new, zero-day email worm is circulating in the wild that exploits an undisclosed vulnerability in Microsoft Word.

According to handlers at SANS Internet Storm Center, victims receive an email with a Microsoft Word attachment that contains a Trojan horse (Trojan.Mdropper.H). When the document is opened, a second Trojan (Backdoor.Ginwui) is launched and tries to connect to a Web server on the Internet to wait for a command.

In a statement, Microsoft said that it is working on a patch for the vulnerability that will be released on June 13 "or sooner as warranted." Microsoft also offered the helpful advice that users should "exercise extreme caution when opening unsolicited attachments from both known and unknown sources."

The exploit requires a user to try to open the Word document, so the chances of automated infection are low. Once the Trojan is launched, it overwrites the infected Word document with a clean copy in an attempt to hide. Symantec's DeepSight threat management team reports that Word 2000 simply crashed, and the Trojan didn't launch. But the exploit was successful in Windows 2003.

SANS handlers said the Trojan also exhibits rootkit functionality by hiding its files from Windows Explorer. The running process and startup registry key is also hidden, according to security company F-Secure.

Experts aren't yet sure which Word vulnerability is being exploited, but analysts at Symantec think it may be a buffer overflow in Word on an OLE component.

Dave Cole, director of Symantec's Security Response Team, doesn't see any need for widespread concern yet. "The attack seemed fairly targeted from one organization to another, and there isn't any exploit code circulating, unlike the Windows Metafile vulnerability circulating over Christmas," Cole says.

"This could be an example of a black market exploit," he adds. "We are not overstating when we say that zero-day [exploits] are being used in targeted attacks. In this case, we have no reason to believe that there will be a widespread attack." If exploit code starts circulating, however, the problem could be more pervasive.

According to the SANS report, the person who discovered the problem noticed discrepancies in an email that appeared to originate from his own domain, and was written in the fashion of an internal email, complete with signature.

— Mike Fratto, Editor at Large, Dark Reading

Organizations mentioned in this story

  • Microsoft Corp. (Nasdaq: MSFT)
  • Symantec Corp. (Nasdaq: SYMC)
  • F-Secure Corp.
  • The SANS Institute

    Mike Fratto is a principal analyst at Current Analysis, covering the Enterprise Networking and Data Center Technology markets. Prior to that, Mike was with UBM Tech for 15 years, and served as editor of Network Computing. He was also lead analyst for InformationWeek Analytics ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 5/22/2020
    How an Industry Consortium Can Reinvent Security Solution Testing
    Henry Harrison, Co-founder & Chief Technology Officer, Garrison,  5/21/2020
    10 iOS Security Tips to Lock Down Your iPhone
    Kelly Sheridan, Staff Editor, Dark Reading,  5/22/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Write a Caption, Win a Starbucks Card! Click Here
    Latest Comment: This comment is waiting for review by our moderators.
    Current Issue
    How Cybersecurity Incident Response Programs Work (and Why Some Don't)
    This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
    Flash Poll
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-13458
    PUBLISHED: 2020-05-25
    An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
    CVE-2020-13459
    PUBLISHED: 2020-05-25
    An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.
    CVE-2020-13442
    PUBLISHED: 2020-05-25
    A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
    CVE-2020-5537
    PUBLISHED: 2020-05-25
    Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.
    CVE-2020-13438
    PUBLISHED: 2020-05-24
    ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.