Hi everyone,
First off on the vulnerability itself: I want to reiterate we’re hard at work on an update. The attack vector here is Word documents attached to an email or otherwise delivered to a user’s computer. The user would have to open it first for anything to happen. That information isn’t meant to say the issue isn’t serious, it’s just meant to clearly denote the scope of the threat.
Now, we’ve received singular reports of attacks and have been working directly with the couple of customers thus far affected. In analyzing the malware we’ve added detection to the
Currently two of the subject lines we have seen are:
Notice
RE Plan for final agreement
The attack we have seen so far requires admin rights, so limitations on user accounts can help here. I want to repeat that customers who believe they are affected can contact Product Support Services. You can contact Product Support Services in
http://support.microsoft.com/security.
So far, this is a *very* limited attack, and most of our antivirus partners are rating this as “low”. But we’re working to investigate any variants we might see to make sure detection is out there, as well as working on the update to address the vulnerability.
S.
PS: