Beware Word docs: New bug crashes Windows XP, 2000

08.03.2007

Microsoft said its security team is looking into the bug. "Microsoft is aware of a report of a possible vulnerability and is currently investigating the issue," said a spokesperson. "The company is not aware of any attacks attempting to use the reported vulnerability or of customer impact at this time, and it will continue to investigate."

Microsoft did not promise it would issue a patch, much less offer a timetable. Until a fix is in place, Symantec and US-CERT recommended that users not open unfamiliar or unexpected Office documents. US-CERT also warned that filtering for standard Office file extensions -- .doc for Office, .xls for Excel, for example -- isn't smart. "In most cases, Windows will call Office to open a document even if the document has an unknown file extension," US-CERT said.