Photo

Reuters Photojournalism

Our day's top images, in-depth photo essays and offbeat slices of life. See the best of Reuters photography.  See more | Photo caption 

Photo

Devastated by Tornado

A huge tornado tears through an Oklahoma City suburb.  Slideshow 

Photo

Message of humility

A religious fraternity in Rio considers the election of Pope Francis, a confirmation of their beliefs in poverty and simplicity.  Slideshow 

Sponsored Links

Microsoft Office users attacked by cybercriminals

Related Topics

Showgoers check the offerings at the Microsoft booth at the annual Consumer Electronics Show (CES) in Las Vegas, Nevada January 9, 2009. REUTERS/Rick Wilking

Showgoers check the offerings at the Microsoft booth at the annual Consumer Electronics Show (CES) in Las Vegas, Nevada January 9, 2009.

Credit: Reuters/Rick Wilking

BOSTON | Tue Jul 14, 2009 5:25pm EDT

BOSTON (Reuters) - Microsoft Corp warned that cybercriminals have attacked users of its Office software for Windows PCs, exploiting a programing flaw that the software giant has yet to repair.

The world's largest software maker issued the warning on Tuesday as it released patches to address nine other security holes in its software.

"Despite today's fixes, Windows users continue to be under attack. Microsoft is taking two steps forward, while attackers are putting it one step back," said Dave Marcus, McAfee Inc's Avert Labs director of security research.

Cybercriminals target Microsoft programs because they are so widely used, allowing them to go after the largest number of potential victims with one set of code. (Windows runs more than 90 percent of the world's PCs. Office has some 500 million users).

Hackers take advantage of the Office vulnerability by booby-trapping websites with malicious code that loads onto computers running Office software. Infected PCs are commandeered into a botnet, a network of hijacked computers. They are used for identity theft, spamming and other cybercrimes.

Microsoft did not say how many machines were attacked.

Users can prevent attacks by disabling functions within the Office software that allow it to work over the Web. Microsoft has posted a tool for doing that on its website -- here

Office XP, 2003 and 2007 are vulnerable to the attacks.

(Reporting by Jim Finkle; Editing by Carol Bishopric and Richard Chang)

Comments (0)
This discussion is now closed. We welcome comments on our articles for a limited period after their publication.