Latest Comments
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM
 
"I actually love the RoboForm software myself. I use it all of the time and it takes all of the ..."
by Omarra Byrd | Nov 18, 2008 8:19 AM

Pre-Patch Tuesday flaws reported in Excel, Internet Explorer 6

  • Email a Friend
  • Print Page
By Dan Kaplan
Jan 9, 2007 3:49 PM
Tags: Pre-Patch | Tuesday | flaws | reported | in | Microsoft | Excel, | Internet | Explorer | 6
Researcher Adrien de Beaupre of the SANS Internet Storm Center said early today that proof-of-concept code is available targeting Internet Explorer 6 (IE) that could lead to a DoS attack.

But a Microsoft spokesman told SCMagazine.com today that the issue actually affects XML [extensible markup language], not IE.

"Microsoft is not currently aware of any active attacks utilising this exploit code or of customer impact at this time," he said. "Microsoft is actively monitoring this situation to keep customers informed and to provide customer guiance as necessary."

The issue was not addressed by this afternoon's patch release, which issued four fixes correcting 10 vulnerabilities.

Meanwhile, vulnerability tracking firm Secunia this morning said a "highly critical" hole in Microsoft Excel could be "exploited by malicious people to compromise a user's system.

"The flaw is caused by an error when opening XLS files that enables an attacker to execute arbitrary code. Jie Ma of Fortinet's security research team discovered the vulnerability.

That flaw, in fact, was repaired with today's security update, namely bulletin MS07-002, although the hole has not impacted any customers, the spokesman said.

Click here to email reporter Dan Kaplan.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Patch Management Whitepapers