Barney's Blog

Blog archive

Patch or Be Attacked

Office is one big hunk of software, and by hunk I don't mean Fabio. After decades of features wars, this thing is bigger than Donald Trump's ego.

And anything that big is hard to protect. So Microsoft relentlessly patches its pride and joy. And hackers unceasingly look for new holes -- and sometime find them in old holes we thought were fixed.

That is the case with a patched hole in Word. This hole let hackers create malicious DLL files and sneak them into e-mails. Once you open the e-mail and then the infected Word doc, you're hosed.

The problem? Hackers know not everyone is up to date with patching. So they continue to attack it.

Well, that attack is back, says Symantec. "The exploit makes use of an ActiveX control embedded in a Word document file," wrote Takayoshi Nakayama, a researcher at Symantec, in a blog post. "When the Word document is opened, the ActiveX control calls fputlsat.dll which has the identical file name as the legitimate .dll file used for the Microsoft Office FrontPage Client Utility Library."

Of course once you are infected the real fun begins. Hackers then blast you malware.

The marker is a file attachment called ftutlsat.dll. Fortunately that file doesn't sound all that tempting.

Posted by Doug Barney on 02/15/2012 at 1:19 PM


Featured

  • Getting a Handle on Hyper-V Virtual NICs

    Hyper-V usually makes it easy to configure virtual network adapters within VMs. That is, until you need to create a VM containing multiple virtual NICs.

  • Microsoft Highlights Emerging Kubernetes Scalability and Governance Efforts

    Microsoft this week highlighted some emerging efforts to improve both the scalability and governance of the open source Kubernetes container orchestration service.

  • Microsoft Ending Azure Container Service Support in 2020

    Microsoft gave notice earlier this month that it will be ending its Azure Container Service on Jan. 31, 2020.

  • Microsoft Releases Surface Diagnostic Toolkit for Business

    Microsoft released a new tool, Surface Diagnostic Toolkit for Business, earlier this month, providing a means for IT pros to find and troubleshoot problems on Microsoft Surface devices.

comments powered by Disqus
Most   Popular

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.