Hackers are exploiting an unpatched vulnerability in Word. That's according to security vendor McAfee, which has warned users of a new Trojan program, called BackDoor-CKB!cfaae1e6, that secretly installs software on a computer.

For the Trojan to work, however, hackers must first trick users into opening a malicious Word document. Once that has been done, though, the results can be nasty.

Unlike viruses and worms,Trojan programs do not make copies of themselves that keep spreading throughout the Internet. Hackers directly distribute the programs, which are often disguised as useful or interesting downloads.

Once installed, the malware lets hackers "execute any external commands, download additional Trojans, capture desktop screen shots, monitor and record keystrokes or passwords," McAfee said in a statement on its website.

Symantec has confirmed that hackers are circulating the malware via malicious Word document email attachments. But at present its use is "limited to attacks against select targets," Symantec said.

The attack originated in Asia and targets "specific large organisations," Symantec said, adding that it has seen similar targeted attacks in the past which also took advantage of flaws in Microsoft Office applications.

The attackers behind the Trojan may be operating from China or Taiwan, according to Johannes Ullrich, chief technical officer of the SANS Internet Storm Center. Servers associated with the attack have been traced back to those countries, and researchers have found Chinese characters in the malicious Word document, Ullrich said.

One company - an unnamed government contractor that reported details of its attack to SANS - said that the malicious email had been sent to only one person in its organisation, and had been written to resemble a normal inter-office message, Ullrich said.

"The exploit was quite sophisticated," he said. "None of the anti-virus systems that they used caught it."

Ullrich said he did not know what the attackers' ultimate goal may be, but they can snoop on data or install unauthorised software once the Trojan gets installed. "It opened up a remote connection to a web site in China that would have allowed it to remotely control [the infected computer]," he said.

SANS has published a number of tips on how to avoid this type of attack. The security training organisation recommends that companies limit users' privileges and monitor outbound traffic. It also suggests that companies think about quarantining all attachments for six to 12 hours in order to give the anti-virus vendors time to catch up with new threats.

Because users must download the malicious software in order to become infected, McAfee rates the risk of the Trojan as "low."

The vulnerability affects Microsoft Word XP and Word 2003, but does not work on computers that use the Word Viewer to view documents, according to Microsoft. Word Viewer is software that lets users read Word documents without installing the Word software.

Microsoft is testing a fix for the Word vulnerability and said it expects to release this as part of its next round of monthly security patches, which are scheduled to be released on 13 June.