, The Register 2005-10-03
Virus writers have created a Trojan which uses an unpatched vulnerability in Microsoft Office to take over Windows PCs. The Hesive Trojan can be disguised as a Microsoft Access file. Once opened in Access, infected .mdb files take advantage of a five-month old buffer overflow flaw in Microsoft's Jet Database Engine software to seize control of vulnerable machines.
Microsoft is yet to fix the Database Engine glitch but the creation of malware specifically targeting a security bug with a core component of Office ought to speed the creation of a fix. ®
