eWeek yesterday ran this story "Third MS Word Code Execution Exploit Posted". It describes the third Word document exploit in a week. There are no current fixes to the other two.
In sports, three strikes and you're out. Microsoft has stood at the plate so many times swinging at the ball and missing it from a security perspective, and they're still not out. While Vista will be an improvement over their existing previous operating systems, there are so many other holes from Office products.
These attacks can be launched by simply opening the document. Therefore the security risk is very high.
Don't stand around waiting to see if Microsoft will ever hit the security ball. Make plans knowing they don't and likely that they won't. Put in place many layers of security to mitigate the risk that your enterprise will receive unwanted malware presents delivered by the MS Office suite.
Guy
www.authenticationworld.com
guy.huntington@authenticationworld.com

del.icio.us