NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Excel Collects Vulnerabilities

A new bug is prep for exploitation

By Marius Oiaga, Technology News Editor

21st of June 2006, 07:27 GMT

Adjust text size:


Excel vulnerabilities are multiplying after Microsoft's 12 patches package was released for Windows, Office and Exchange. The first flaw, tagged as critical because it allows for remote
code execution, was exploited in an isolated case of zero-day attack just last week, the latest vulnerability was made public yesterday.

Both Symantec and Secunia have revealed that the vulnerability is a direct result of how a DLL manages the Hyperlinks in an Excel worksheet and that the problem emerges with the execution of a URL link in an Excel document. The proof-of-concept exploitation code has already been made public, both companies say, but their opinions on how this might be used by an attacker are divided.

"The vulnerability is caused due to a boundary error in hlink.dll within the handling of Hyperlinks in Excel documents. This can be exploited to cause a stack-based buffer overflow (an anomaly where the process will attempt to store data beyond the boundaries of the hardware registries or the allocated memory) by tricking a user into clicking a specially crafted Hyperlink in a malicious Excel document. Successful exploitation allows execution of arbitrary code. The vulnerability has been confirmed in Microsoft Excel 2003 SP2 (fully updated). Other versions and Office products may also be affected," warned Secunia.

Unlike them, Symantec does not believe that the possibility of code execution exists and after examining the proof-of-concept code, it says that the code does not contain a payload and will only cause the process to crash.

Both security companies have advised against opening or following links in Office documents.
Read by 780 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Very Good (4.2/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Offers Support on Excel Bug

New Microsoft Vulnerability

Microsoft Loses Another Lawsuit

Office 2007 Will Have the Ultimate

Excel to Become Strategic Trading Platform

Symantec Updates Its Vulnerable Products

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM