On TechRepublic: Why VISTA HATERS will love Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jun 20, 2006 7:53:00 PM

Attack code for a new security hole in Excel has surfaced on the Internet, just as Microsoft is scrambling to respond to a separate bug in the spreadsheet program.

The latest vulnerability could cause Excel to crash after a malicious file is opened, according to an alert Symantec sent to customers on Monday. The security company also said there was a risk that an intruder could commandeer a PC. "Attackers may also be able to execute arbitrary code…but this has not been confirmed," it said.

The security hole exists because Excel fails to properly check user-supplied input before copying it to an insufficiently sized memory buffer, Symantec said. Excel 2003 and Excel XP are vulnerable, and other versions may also be affected, Symantec said.

Security monitoring company Secunia deems the issue "highly critical," one notch below its most severe ranking, according to an alert it published on Tuesday.

Sample computer code that exploits the flaw is publicly available on the Net. However, Secunia said it is not aware of any current attacks using the security hole.

Microsoft is looking into the issue, a company representative said in a statement Tuesday. "Based on our investigation, the issue is a new vulnerability in Microsoft Windows that may be exploited when clicking on a hyperlink with Office documents," the representative said. Microsoft is not aware of any attacks that exploit this flaw, he added.

The latest Excel vulnerability comes just as Microsoft is grappling with another yet-to-be-patched bug in the spreadsheet application. That flaw, disclosed late last week, could give an attacker full control over a vulnerable PC and has been exploited in at least one targeted cyberattack, Microsoft has said.

To exploit either one of the new flaws, an attacker would craft a malicious Excel file and host that file on a Web site, send it via e-mail, or otherwise provide it to the intended victim. The attempt can be successful only if the file is opened on a vulnerable PC.

Both vulnerabilities come on the heels of Microsoft's "Patch Tuesday" batch of security updates. Last week, Microsoft released 12 patches that addressed 21 vulnerabilities in various products, including Office applications. The company has said it is working on a patch for the first new Excel flaw.

Some experts believe the timing of the new exploits is no coincidence, as miscreants will have a month until patches are available. Microsoft typically does not release fixes outside of its monthly patching cycle for such flaws, these experts said.

On Monday, Microsoft posted tips for users to respond to the first Excel flaw, which affects all versions of the software, including those for Apple Computer's Mac OS. Microsoft suggests caution when opening Excel files. It also recommends blocking such files when they arrive as e-mail attachments or changing PC settings so spreadsheets can't be opened from the Outlook e-mail client or the Web.

For Excel 2003, Microsoft recommends that people prevent the application from running in "repair mode" by modifying some settings in the Windows Registry. The flaw is exploited in that special mode, Microsoft said in a security advisory on the issue.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 40 Talkback(s)
Get a life Milky
NT (Read the rest)
Posted by: Cayble Posted on: 06/30/06 You are currently: a Guest | | Terms of Use
Was it that Google spreadsheet  Boot_Agnostic | 06/20/06
FWIW, if you use IE, it does warn you before opening Excel files  PB_z | 06/20/06
The problem with these types of exploits is that someone gets infected.  MacGeek2121 | 06/20/06
But it is faster than open office  jjanks | 06/20/06
selam  hagus | 06/20/06
Why is it, so incredibly hard for MS to completely patch  michael_t | 06/20/06
Why pop a blood vessel?  scottie_clark@... | 06/20/06
MS needs to hire them  Boot_Agnostic | 06/20/06
Never mind him, he can't help himself  Code Poet | 06/20/06
He has issues...  Cayble | 06/20/06
I disagree.  MageOfChaos | 06/20/06
Actually, I agree totally  Cayble | 06/20/06
Sorry.  MageOfChaos | 06/21/06
much less than your beloved MS trashware wink  michael_t | 06/20/06
Still hooked on no-doze I see  byeats | 06/21/06
Relax... talking the OBVIOUS truth out is very soothing ... n  michael_t | 06/20/06
RE : Why pop a blood vessel?  dlbear | 06/22/06
You need a hobby other than ZD net  Code Poet | 06/20/06
my favorite lame excuse for the last 20 years  not of this world | 06/20/06
I'll tell you why...  Wolfie2K3 | 06/20/06
Ho ho ho ho ... the entire "Special Club" had its gathering .... wink  michael_t | 06/20/06
I disagree  byeats | 06/21/06
Convenience has killed Quality  michael_t | 06/21/06
Again, you are 100x safer using OpenOffice. Ditch the bug-ridden thing they  DonnieBoy | 06/20/06
Not to mention  jflash_z | 06/20/06
Open office is substandard  Code Poet | 06/20/06
I have not installed OpenOffice for a long time, it comes with almost all  DonnieBoy | 06/20/06
So get the Neo- Office distro  s_gamgee | 06/21/06
That should be your first clue...  Spikey_Mike | 06/22/06
ODF is an official standard  not of this world | 06/20/06
funny funny funny, is this real life or TV??  jonathan swift | 06/20/06
Windows future...  interested_amateur@... | 06/20/06
they should be yelling INCOMING!!  warezdog | 06/20/06
I'm in the same mood  Castanet | 06/20/06
Yet another vicious cycle of trying to patch some MS product happy  michael_t | 06/21/06
I'm no MS lover...I don't like MS....  mdsmedia | 06/22/06
If only you'd press your companies to use other offices  Boot_Agnostic | 06/22/06
I ask from my ignorance.  jolumoar | 06/23/06
No, these are exclusively MS office issues (as usual happy ) ...nt  michael_t | 06/23/06
Get a life Milky  Cayble | 06/30/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

advertisement
Click Here