Microsoft Warns of Vulnerability in Microsoft Word

Microsoft recently warned of a particular vulnerability in Microsoft Word, specifically the 2010 version. This vulnerability is a defect when a user opens an RTF file with Word. This includes when a users uses Outlook, as Outlook uses Word as its default email viewer. When exploited, Microsoft Word parses a particular RTF file, and the computer’s memory can become compromised. This gives the attacker access to the users computer with the same rights as the user. While standard users may be less affected by the attack, users with administrator rights become more vulnerable. While Microsoft Word 2010 seems to be the most at risk, Microsoft notes that Word 2007 and 2013 also contain the vulnerability. While Microsoft says Word 2013 can be exploited, current research suggests the attack attempt crashes when executed in 2013.

Microsoft has released one of their Fix It tools in order to patch the vulnerability.

New Microsoft Word Zero-Day Used in Targeted Attacks- SecurityWeek.com
Microsoft Advisory and Fix It