Microsoft: To Avoid Zero-Day Attack, Use MS Word in Safe Mode | CIO Insight

Microsoft: To Avoid Zero-Day Attack, Use MS Word in Safe Mode

Written By
Ryan Naraine
Ryan Naraine
May 23, 2006
1 minute read

Use Microsoft Word in safe mode to protect against targeted zero-day attacks.

That’s the advice from Microsoft’s security response team to counter known attacks against a serious code execution vulnerability in the widely used word processing program.

In a pre-patch security advisory, Microsoft said the flaw can be exploited when a user opens a specially crafted Word file using a malformed object pointer.

This corrupts system memory in such a way that an attacker could execute arbitrary code.

The flaw can be exploited via the Web or via e-mail but, in both scenarios, an attacker would have to trick a user into opening the rigged Word file.

In the absence of a patch, independent security researcher Matthew Murphy has released a registry script fix that sets a Software Restriction Policy that runs any instance of ‘winword.exe’ with the ‘Basic User’ policy.

Read the full story on eWEEK.com: Microsoft: Use MS Word in Safe Mode

CIO Insight Logo

CIO Insight offers thought leadership and best practices in the IT security and management industry while providing expert recommendations on software solutions for IT leaders. It is the trusted resource for security professionals who need to maintain regulatory compliance for their teams and organizations. CIO Insight is an ideal website for IT decision makers, systems integrators and administrators, and IT managers to stay informed about emerging technologies, software developments and trends in the IT security and management industry.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.