Vulnerability Research - Microsoft Confirms Zero-Day Word Flaw - eWeek Security Watch

Microsoft Confirms Zero-Day Word Flaw

Written By
Matthew Hines
Matthew Hines
Feb 1, 2007
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft has confirmed that a vulnerability being used in a wide number of targeted zero-day attacks is an unpatched flaw in its Word program.

According to a post on Symantec’s Security Response blog by researcher Eric Chien, Microsoft has verified that the unspecified Code Execution Vulnerability (labeled CVE-2006-6456 by the software maker) is being used to deliver zero-day malware code by attackers.

Since the vulnerability remains unpatched, Symantec is advising users to be wary of opening any unsolicited Word documents that may be sent to them via e-mail.

On Tuesday, Symantec posted its initial report of the attacks that are exploiting the issue, which it named Trojan.Mdropper.X.

The security specialist said that while the documents being used in the targeted attacks are consistent with previous threats it has tracked, Symantec has received different documents using the exploit tailored to threaten a handful of different organizations.

Each of the malicious Word documents is designed to lure users within specific organizations into opening them, including through the use of unique language and content.

The company said the latest vulnerability represents the fifth known unpatched Office file format flaw currently identified by its researchers.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.