iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Zero Day Excel Threat Vexes Microsoft
Search:
[ insider_reports_insider ]

Zero Day Excel Threat Vexes Microsoft



David Utter
Staff Writer
2008-01-17

SecurityProNews: Insider Reports Insider Reports RSS Feed


Public disclosure of a newly found vulnerability in several versions of the Microsoft Excel spreadsheet program have the software company racing to repair it.

Zero Day Excel Threat Vexes Microsoft
Zero Day Excel Threat Vexes Microsoft

When someone drops details of a flaw on the Internet, especially those related to remote code execution, it places users of the software at virtually an immediate risk. With the software being Excel, arguably the most important piece of Office and in use on millions of desktops globally, the threat increases dramatically.

In the latest Microsoft security advisory, the company again took those responsible for publicly disclosing a vulnerability to task. "We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed," the advisory said.

There are arguments for and against such public disclosure. We won't recount those here, other than to note that once upon a time, software companies were not nearly as responsive to submitted security vulnerability reports as they are today.

In this latest advisory, several version of Excel, and including the Microsoft Office Excel Viewer 2003, could fall victim to an exploit. Microsoft said the vulnerability could be exploited when a user opens a specially crafted file.

To succeed, an attacker has to convince someone to either open a malicious Excel file attached to an email. Or, the file could be hosted on a website where the criminals would try and get people to download it.

Excel versions 2000 through 2007, and Excel 2004 and 2008 for Mac, suffer from the vulnerability. Microsoft has not decided whether to issue a fix as part of a monthly patch update, or to release an out-of-band patch. Microsoft rarely goes out-of-band with its updates; if this vulnerability is not being vigorously exploited, it's likely they will wait until February at the earliest to correct it.



About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds