Barney's Blog

Blog archive

Patch or Be Attacked

Office is one big hunk of software, and by hunk I don't mean Fabio. After decades of features wars, this thing is bigger than Donald Trump's ego.

And anything that big is hard to protect. So Microsoft relentlessly patches its pride and joy. And hackers unceasingly look for new holes -- and sometime find them in old holes we thought were fixed.

That is the case with a patched hole in Word. This hole let hackers create malicious DLL files and sneak them into e-mails. Once you open the e-mail and then the infected Word doc, you're hosed.

The problem? Hackers know not everyone is up to date with patching. So they continue to attack it.

Well, that attack is back, says Symantec. "The exploit makes use of an ActiveX control embedded in a Word document file," wrote Takayoshi Nakayama, a researcher at Symantec, in a blog post. "When the Word document is opened, the ActiveX control calls fputlsat.dll which has the identical file name as the legitimate .dll file used for the Microsoft Office FrontPage Client Utility Library."

Of course once you are infected the real fun begins. Hackers then blast you malware.

The marker is a file attachment called ftutlsat.dll. Fortunately that file doesn't sound all that tempting.

Posted by Doug Barney on 02/15/2012 at 1:19 PM


  • Microsoft Nabs IoT Platform Provider Express Logic

    As part of its plan to invest $5 billion in IoT technologies, Microsoft this week acquired Express Logic, which provides real-time operating systems for industrial embedded and IoT devices.

  • Dealing with Broken Dependencies in SCVMM

    Brien shows you how to resolve some broken, template-related dependencies in Microsoft's System Center Virtual Machine Manager.

  • AzCopy Preview Adds AWS S3 Data Transfer Improvements

    Microsoft announced this week that it has improved the preview version of its AzCopy tool to better handle Amazon Web Services (AWS) S3 data.

  • Microsoft Adding Google G Suite Migration in Exchange Admin Center

    Microsoft's Exchange Admin Center will be getting the ability to move Google G Suite calendar, contacts and e-mail data over to the Office 365 service "in the coming weeks."

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.