Document Malware Current Threats


The chart below contains an overview of the most common document format exploits (see PDF Threats for PDF and Flash threats.) Targeted malware attacks, sometimes called "spear phishing" use Microsoft Office documents from Word, Excel and Powerport, RTF, CHM, and PDF.

Scan your documents for malware with Cryptam.

More info on our PDF Examiner for detection and analysis of malicious PDFs.

Current Office Document threatcon High: Reports of a new MS Office .doc zero day part of the Duqu malware threat in the wild. Patched Office and Flash exploits being actively targeted. No reported .docx (Office XML format) vulnerabilities.

ReleaseCVE IDDescriptionExploitStatusExploitabilityPatchMWTracker Sample

2011-04-11

CVE-2011-0611

Adobe Flash embedded in Microsoft Word or Excel. Possible author @yuange1975. Reported by Mila Parkour.

Adobe Flash zeroday. See the Adobe advisory for more information.

patched

Targeted attacks

2011-04-15 > Flash 10.2.159.1

n/a report one

2011-03-14

CVE-2011-0609

Adobe Flash embedded in Microsoft Excel (also affects PDF). Possible author @yuange1975. Used in RSA compromise. Reported by Mila Parkour.

Adobe Flash zeroday, 1-byte fuzzing. See the Adobe advisory for more information.

patched

high

2011-03-21 > Flash 10.2.152.33

n/a report one

2010-11-09

CVE-2010-3333

MS Office Word/RTF exploit remote code execution. By Wu Shi of team509.

Microsoft Office/Word RTF exploit Advisory 2423930

patched

High

2010-11-09 MS10-087

n/a report one

2011-01-04

CVE-2010-3970

Thumbnail exploit in Windows - Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor. By By Moti Joseph and Xu Hao.

Microsoft Windows thumbnail Advisory 2490606

patched

Low

2011-02-08 MS11-006

n/a report one

2009-11-10

CVE-2009-3129

Microsoft Excel FEATHEADER Record Memory Corruption. By Sean Larsson.

Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution Advisory 972652

patched

High

2009-11-10 MS09-067

n/a report one

2009-06-09

CVE-2009-0557

Microsoft Excel remote exploit. By Bing Liu of Fortinet.

malformed record object Advisory 969462

patched

Low

2009-06-09 MS09-021

n/a report one

2009-04-02

CVE-2009-0556

Microsoft Powerpoint remote exploit. By Marsu Pilami.

Microsoft Powerpoint Boundary Condition Error Advisory 969136

patched

Medium

2009-05-12 MS09-017

n/a report one

2008-12-09

CVE-2008-4841

WordPad / Microsoft Word malformed list structure. By unknown.

malformed list Advisory 960906

patched

Low

2009-04-14 MS09-010

n/a report one

2008-08-12

CVE-2008-3005

Array index vulnerability in Microsoft Office Excel. By VeriSign.

array index Advisory 954066

patched

Low

2008-08-12 MS08-043

n/a report one

2008-01-15

CVE-2008-0081

Microsoft Excel Macro Validation Vulnerability. By Mike Scott of SAIC and Matt Richard of VeriSign.

Input Validation Error Advisory 947563

patched

Low

2008-03-08 MS08-014

n/a report one

2007-02-13

CVE-2006-6456

Microsoft Word specially crafted data structure. By McAfee.

Microsoft Word Advisory 929434

patched

Low

2007-02-13 MS07-014

n/a report one

2006-07-11

CVE-2006-2389

Microsoft Office document parsing vulnerability.

>Microsoft Office Advisory 917284

patched

High

2006-07-11 MS06-038

n/a report one

2005-05-10

CVE-2006-2492

Microsoft Word Malformed (SmartTag) Object Pointer vulnerability. By Shih-hao Weng.

malformed object pointer Advisory 919637

patched

High

2005-06-13 MS06-027

n/a report one

1997

Design Flaw

Microsoft Compiled HTML Help can contain and run executables.

.CHM files run from local zone

ongoing

High

n/a report one



Please contact us for more information.

This page was last updated 2012-02-09 13:55:06