Microsoft Word Zero-Day Vulnerability is being exploited in the Wild
Mar 25, 2014
Microsoft warned about a zero-day vulnerability in Microsoft  Word that is being actively exploited in targeted attacks and discovered by the Google security team. " At this time, we are aware of limited, targeted attacks directed at Microsoft Word 2010… " company said.  According to Microsoft's security advisory , Microsoft Word is vulnerable to  a remote code execution vulnerability ( CVE-2014-1761 ) that can be exploited by a specially crafted Rich Text Format (RTF).  An Attacker can simply infect the victim's system with malware if a user opens a malicious Rich Text Format (RTF), or merely preview the message in Microsoft Outlook.  " The issue is caused when Microsoft Word parses specially crafted RTF-formatted data causing system memory to become corrupted in such a way that an attacker could execute arbitrary code. "  Microsoft acknowledged that remote code execution  flaw also exists in Microsoft Word 2003, 2007, 2013, Word Viewer and Office for Mac ...