Second Word 0-day for December 2006 Disclosed
Following our previous post on the first Word 0-day disclosure, we now see that there's yet another Word 0-day exploit in the wild. The latest Word 0-day implements a buffer overflow attack against a vulnerability in Word, and installs a password sniffing trojan.
It looks like Halvar Flake's statement about how we're going to see a slew of MS Office 0-day exploits due to Vista features is already happening.
