On TechRepublic: Badly configured laptop ruins man's life
BNET Business Network:
BNET
TechRepublic
ZDNet

By Elinor Mills
Posted on ZDNet News: Jul 7, 2006 1:15:00 AM

A hole in Microsoft Excel has been identified that could allow attackers to take control of a computer, a security group said Thursday--the third vulnerability affecting the popular spreadsheet program to surface in less than a month.

The flaw is due to a memory corruption error that occurs when handling or repairing a document containing overly long styles, the French Security Incident Response Team said in an advisory.

The flaw, which affects Excel 2000, 2002 and 2003 and Office 2000, XP and 2003, "could be exploited by attackers to execute arbitrary commands by convincing a user to open and repair a specially crafted Excel file," the advisory said.

A Microsoft representative said the company is investigating reports of a new vulnerability in Excel and was not aware of any attacks related to it.

"In order for this attack to be carried out, a user must first open a malicious Excel document that is sent as an e-mail attachment or otherwise provided to them by an attacker," the representative said in an e-mail. "Opening the Excel document out of e-mail will prompt the user to be careful about opening the attachment."

The vulnerability affects only users of Japanese, Korean or Chinese language versions of Excel, the Microsoft representative said.

Customers who believe they are affected can get more information on Microsoft's security Web site. For more information about protecting a computer from threats, Microsoft has this site.

Excel hackers have been busy. On June 16, experts warned about a hole that was exploited in at least one targeted cyberattack. About two weeks ago, an Excel hole was discovered that could crash the program after a malicious file is opened.

  • Talkback
  • Most Recent of 44 Talkback(s)
Your users?
LD, your users are geriatrics patients in a retriment home. Of course they are going to cancel!

All,
LD is a low level hospital tech who cleans bed pans.
Or, as I have commented on befor... (Read the rest)
Posted by: DangDaCommonCentz Posted on: 07/10/06 You are currently: Logged In | Log out
Another security hole found in Excel Loverock Davidson   | 07/06/06
You Are Worse Than A Cult Member itanalyst   | 07/07/06
He is the cult's grand-poobah! Reverend MacFellow   | 07/07/06
Did I read that right xuniL_z   | 07/07/06
Hes a Jackass, but hes correct this time Cayble   | 07/07/06
wha-wha-what? Sxooter_z   | 07/07/06
Sorry swoopee   | 07/07/06
You heard me Loverock Davidson   | 07/07/06
Explain Dave P.   | 07/07/06
my experience is they read them corticus   | 07/07/06
Lucky You Dave P.   | 07/07/06
Explain? Loverock Davidson   | 07/07/06
Loverock Dave P.   | 07/07/06
Your users? DangDaCommonCentz   | 07/10/06
Tell me Dave P.   | 07/07/06
tee hee hee Loverock Davidson   | 07/07/06
Trust me, I wasn't being funny Dave P.   | 07/07/06
I think you were Loverock Davidson   | 07/07/06
Then you'd be... Dave P.   | 07/07/06
Correction Dave P.   | 07/07/06
Correction to you correction Loverock Davidson   | 07/07/06
Correction to the corrected correction Dave P.   | 07/07/06
oh, you never did answer my question Dave P.   | 07/07/06
The fix for this problem however is due gotitright   | 07/09/06
Catching Up Dave P.   | 07/07/06
Starve the troll ^ (nt) LoCal   | 07/06/06
Did Microsoft write this themselves? Scrat   | 07/07/06
After the WGA snafu, I find that less and less difficult to believe. MageOfChaos   | 07/07/06
But what did the Japanese do? Reverend MacFellow   | 07/07/06
Sushi chef swoopee   | 07/07/06
The current version of Microsoft Office: Not safe at any speed. DonnieBoy   | 07/07/06
HAHAHAHAHA! Confused by religion   | 07/07/06
Because that's always worked in the past Sxooter_z   | 07/07/06
sorry Sxooter_z   | 07/07/06
Office is better because it HAS Access corticus   | 07/07/06
Your point? Dave P.   | 07/07/06
oooo! Dave P.   | 07/07/06
Open Office means Security Sieve Office…Read Cayble   | 07/09/06
Let's do some research... gotitright   | 07/09/06
User Interface Dave P.   | 07/07/06
Who copies whom? Confused by religion   | 07/07/06
Bzzt - wrong answer Dave P.   | 07/07/06
No offense, but you're an @$$. MageOfChaos   | 07/08/06
Gee, my head just exploded in sheer abject surprise. HypnoToad72   | 07/08/06

What do you think?

advertisement
advertisement