Latest Comments
"it's good one "
by khanbhai | Nov 22, 2008 9:00 PM
 
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM

Excel exploit targets vulnerability in the wild

  • Email a Friend
  • Print Page
Excel exploit targets vulnerability in the wild
By Frank Washkuch
Jan 17, 2008 4:21 PM
Tags: Excel | exploit | targets | vulnerability | in | the | wild
The issue exists in Excel versions 2003 with Service Pack 2, Viewer 2003, 2002 and 2000 for Windows, as well as Excel 2004 for Mac, according to an advisory released Tuesday by Microsoft.

The flaw does not exist on Excel versions 2003 with Service Pack 3, 2007, 2007 with Service Pack 1 for Windows, and Excel 2008 for Mac, according to Microsoft.

The Redmond, Wash.-based software giant revealed that it is aware of only targeted attacks leveraging the flaw. Due to limited public knowledge, risk of exploitation is limited, according to Microsoft.

The issue is caused by a memory corruption error when handling header information, according to FrSIRT, the French Security Incident Response Team, which ranked the flaw as “critical.”

Secunia, a Copenhagen-based vulnerability monitoring organization, ranked the flaw “extremely critical,” meaning exploits seeking to run arbitrary code are in the wild.

US-CERT advised users to not open unfamiliar or unexpected email attachments and employ Microsoft's recommended workarounds.

The issue can be exploited via email or a specially crafted website. For a message-based attack, a victim would have to open an Excel attachment, while a web-based scenario exposes the user to exploitation from sites that feature user-created content, according to Microsoft, which urged users to employ the Office Isolated Conversion Environment or Office File Block Policy, if available, to view messages.

Bill Sisk, Microsoft Security Response communications manager, said Tuesday on a company blog that employees are working on a fix, but did not give a timeline for release.

“As part of our SSIRP [Software Security Incident Response Process], we currently have teams working to develop an update of appropriate quality for release in our regularly scheduled bulletin process or as an out-of-band update, depending on customer impact,” he said. “In the meantime, we encourage customers to review the advisory and implement the workarounds.”

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Access Control Whitepapers