Excel Remote Code Execution Zero Day

By admin | Jan 17, 2008
If you are new here, you may want to subscribe to our feed.

A zero day vulnerability is like a candy shop for hackers.  It allows them a proven vulnerability with no remedy.  In any case, a zero day for Excel has just come into play.  And, as implied earlier, there is not remedy right now.  Well, except that you not open untrusted Excel documents.

From M$ Technet:

Microsoft is investigating new public reports of a vulnerability in Microsoft Office Excel 2003 Service Pack 2, Microsoft Office Excel Viewer 2003, Microsoft Office Excel 2002, Microsoft Office Excel 2000, and Microsoft Excel 2004 for Mac. At this time, our initial investigation indicates that customers who are using Microsoft Office Excel 2007 or Microsoft Excel 2008 for Mac, or who have installed Microsoft Office Excel 2003 Service Pack 3 are not affected by this vulnerability.

Microsoft is investigating the public reports and customer impact. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.

At this time, we are aware only of targeted attacks that attempt to use this vulnerability. Additionally, as the issue has not been publicly disclosed broadly, we believe the risk at this time to be limited.”

Versions affected:

Microsoft Office Excel 2007

Microsoft Office Excel 2003

Microsoft Office Excel Viewer 2003

Microsoft Office Excel 2002

Microsoft Office Excel 2000

Microsoft Excel 2004 for Mac

Microsoft Excel 2008 for Mac



Related Posts:

Microsoft Excel Repair Mode Vulnerability
And yet again, Secunia has issued an extremely critical security warning. This time it involves a memory corruption issue...

Critical Trillian, WinAmp Security Flaws
Heads up for two newly flagged issues if you use either the online instant messaging program "Trillian", and the media...

Real Player Problems
Real Networks has issued a bulletin and patches for a recent string of vulnerabilities. The vulnerabilities are: Exploit 1: To...

Windows Animated Cursor Zero Day Exploit
An exploit has been found that allows remote code execution with privileges of the logged in user. Here lies...

Adobe PNG File Handling Buffer Overflow
This sort of exploit is harder to pull off because of the need for user action. But, as PT...

Leave a Comment

If you would like to make a comment, please fill out the form below.

Name (required)

Email (required)

Website

Comments

© 2007 PaulTech Network, - Daily Blog Tips Themes