PandaLabs said that the security hole is exploited through specially crafted Access files (.mdb) embedded with malicious code.
The flaw is being used to distribute the Keylogger.DB Trojan which is designed to steal confidential data by logging keystrokes.
PandaLabs said that this is a similar security problem to that discovered a few months back, categorised as CVE-2007-6026, but the new flaw also affects the msjet40.dll library, albeit at a different point.
Luis Corrons, technical director of PandaLabs, said: "Whenever a vulnerability of this type appears cyber-crooks will try to take full advantage.
"We can therefore expect to see more malicious Access files in circulation that contain this Trojan and other types of threat."
Cyber-criminals exploit Access flaw
By
Robert Jaques
on Mar 7, 2008 8:28AM

Got a news tip for our journalists? Share it with us anonymously here.
Partner Content

Tech For Good program gives purpose and strong business outcomes

Kaseya Dattocon APAC 2024 is Back

Build cybersecurity capability with award winning Fortinet training from Ingram Micro

Channel can help lead customers to boosting workplace wellbeing with professional headsets

How NinjaOne Is Supporting The Channel As It Builds An Innovative Global Partner Program
Sponsored Whitepapers
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan

Pulseway Essential Eight Framework

7 Best Practices For Implementing Human Risk Management

2025 State of Machine Identity Security Report