March 21, 2010

2/24: Mdropper.XR Trojan Exploits Zero-Day Flaw in Versions of Office

Troj_Mdropper.XR is the Trend Micro detection for a specially crafted MS Excel file that exploits a zero-day vulnerability in certain Microsoft Office Versions. They are:

  • Microsoft Office 2000 Service Pack 3
  • Microsoft Office 2003 Service Pack 1 or Service Pack 2
  • Microsoft Office XP Service Pack 3

    It may be dropped by other malware. It may also be downloaded unknowingly by a user when visiting malicious Web site(s).

    Upon execution and the subsequent exploit of the affected system, this Trojan drops and executes BKDR_AGENT.FAX in the current user's Temporary folder.

    As a result, the routines of the dropped backdoor are exhibited on the affected system.

    Technical details can be found at this Trend Micro page.

  • 1
    IT Offers

    Partners