Microsoft is warning Word users of attackers exploiting a newly discovered - and "extremely critical" - vulnerability.
Microsoft advised caution in opening email attachments and viewing websites, saying that, to infect a PC, an attacker must first dupe a targeted user into opening a malicious Word file.
Alexandra Huft, Microsoft security program manager, said on the Microsoft Security Response Center blog today that her company is aware of "very limited, targeted" attacks attempting to use exploit the flaw.
The vulnerability is caused due to an unspecified error when parsing Word documents, according to the vulnerability-reporting clearinghouse. The flaw exists in Word 2000, but other versions may also be affected.
Researchers at Symantec disclosed the flaw, also saying the issue is "extremely critical."
"An attacker could exploit this issue by enticing a victim to open a malicious Word file," according to Symantec. "If the attack is successful, the attacker may be able to execute arbitrary code in the context of the currently logged-in user."
Click here to email Online Editor Frank Washkuch Jr.