[11152] in bugtraq

home help back first fref pref prev next nref lref last post

word 97 macrovirus protection problem

daemon@ATHENA.MIT.EDU (thomas lakofski)
Tue Jul 27 20:33:38 1999

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.LNX.3.96.990726222204.21525C-100000@oi>
Date:         Mon, 26 Jul 1999 22:37:53 +0000
Reply-To: thomas lakofski <thomas@88.net>
From: thomas lakofski <thomas@88.NET>
X-To:         bugtraq@securityfocus.com, ntbugtraq@listserv.ntbugtraq.com
To: BUGTRAQ@SECURITYFOCUS.COM

hi,

i recently noticed, while dealing with a macro virus going around my
office (too new for latest av software), that word 97's 'macro virus
protection' feature doesn't work when printing documents directly from
explorer.

normal scenario:

1) open document
2) word pops up macro warning dialog
3) click 'disable'
4) open visual basic editor and delete the module containing the virus

but, if like i was, you're printing a few documents and one happens to
have a virus:

1) select multiple documents
2) right click, select 'print' context menuitem
3) word opens each document sequentially and prints them, including the
document with a virus in it.  word doesn't ask about the macros in this
document, just goes ahead and enables them anyway.
4) i now have a macro virus in my normal.dot, with no indication of ever
having run a macro-containing file.

[skip rant on stupid macro security model]

regards,

-thomas

......
[obligatory-useless-waste-of-bits-bit-goes-here] ultra-umbra-magic-crypto
EF D8 33 68 B3 E3 E9 D2  C1 3E 51 22 8A AA 7B 98 supercomputer-AES-xspook

home help back first fref pref prev next nref lref last post