New Windows Vulnerability
October 22, 2014
The Microsoft Security Advisory describes a new, un-patched vulnerability in all currently supported versions of Windows except Server 2003. Successful exploitation of this vulnerability would allow an attacker to gain the same rights on the machine as the current user.
Exploitation of this vulnerability requires the user to open a specially crafted Microsoft Office document. Researchers are seeing targeting attacks utilizing this attack.
Prevention: standard behavior rules apply:
- Don’t open attachments from unknown sources
- Don’t click on suspicious links in email