updated 06:55 pm EDT, Thu April 18, 2002
c|net points to a serious flaw in Microsoft Office 2001 and v.X for the Macintosh -- only recently acknowledged by the software giant -- that would leave a user's system open to Internet 'vandals' and computer worms. Malicious hackers can cause a complete system crash of Mac OS 9, or an application crash in Mac OS X by formatting HTML in a particular manner and taking advantage of the software's built-in HTML engine. Discovered by the w00w00 security group, the method can result in loss of work, or just simple annoyance. "In all cases, writing shellcode (a program) to exploit this problem is simple." A patch to correct the hole is now available from Microsoft; OS X users can get the update via the Apple Software Update application; a Microsoft Office X Combined Update also addresses the issue; a small patch is available for Mac OS 9.