Exploit in Microsoft Word lets hackers infiltrate systems

Windows logo
The exploit allows hackers to jump from user to user

Microsoft has warned of a vulnerability that exists in its Word 2010 software that is being exploited in targeted attacks by cybercriminals and affects the popular Rich Text Format filetype.

The vulnerability, listed in an advisory, is caused when Microsoft Word parses RTF-formatted data. This can cause system memory to become corrupted, making it easier for an attacker to execute arbitrary code.

An attacker could host a website with specially crafted RTF file types to create this vulnerability, or create and host content designed to exploit any system that may have been already affected. Infection is usually achieved through malicious links in emails to the host's computer.

Worries on Word

Once inside a system, the criminal will be able to infect other users with the same rights. If an administrative account is compromised, every other user on that machine may be at risk.

Microsoft has said that it is working with partners to increase the information on offer and to give their customers, the necessary tools to shield themselves from the exploit.

As a possible temporary fix, the company is asking users to disable RTF content in Microsoft Word, read their emails in plain text and use file blocking policies to prevent malicious content from appearing in emails and messages.

Latest in Software & Services
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
Autonomous finance
Quickbooks vs Quicken: what are the main strengths and weaknesses for your business
finance
Quickbooks vs Xero: which is the best for your business?
Group of people meeting
Zoom vs Google Meet: which is the best video conferencing tool for your business?
Fingers typing on a computer keyboard.
Microsoft 365 Personal vs Microsoft 365 Family: are there any real differences?
Person at laptop
Windows 11 vs Windows 365: which is the best choice for businesses?
Latest in News
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough