Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft

June 21st, 2006, 07:27 GMT · By

Excel Collects Vulnerabilities

SHARE:

Adjust text size:


Excel vulnerabilities are multiplying after Microsoft's 12 patches package was released for Windows, Office and Exchange. The first flaw, tagged as critical because it allows for remote
code execution, was exploited in an isolated case of zero-day attack just last week, the latest vulnerability was made public yesterday.

Both Symantec and Secunia have revealed that the vulnerability is a direct result of how a DLL manages the Hyperlinks in an Excel worksheet and that the problem emerges with the execution of a URL link in an Excel document. The proof-of-concept exploitation code has already been made public, both companies say, but their opinions on how this might be used by an attacker are divided.

"The vulnerability is caused due to a boundary error in hlink.dll within the handling of Hyperlinks in Excel documents. This can be exploited to cause a stack-based buffer overflow (an anomaly where the process will attempt to store data beyond the boundaries of the hardware registries or the allocated memory) by tricking a user into clicking a specially crafted Hyperlink in a malicious Excel document. Successful exploitation allows execution of arbitrary code. The vulnerability has been confirmed in Microsoft Excel 2003 SP2 (fully updated). Other versions and Office products may also be affected," warned Secunia.

Unlike them, Symantec does not believe that the possibility of code execution exists and after examining the proof-of-concept code, it says that the code does not contain a payload and will only cause the process to crash.

Both security companies have advised against opening or following links in Office documents.

TELL US WHAT YOU THINK:

1,048 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Offers Support on Excel Bug

New Microsoft Vulnerability

Microsoft Loses Another Lawsuit

Office 2007 Will Have the Ultimate

Excel to Become Strategic Trading Platform

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM