Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Virus alerts

August 5th, 2009, 13:18 GMT · By

Flash Vulnerability Exploited Through Excel Spreadsheets

SHARE:

Adjust text size:


Excel spreadsheets used to exploit recent Flash vulnerability
Enlarge picture
Cybercrooks have found a new way to exploit a recently patched critical Flash vulnerability, which has been used to infect Web surfers with malware since July. The new technique involves malicious SWFs embedded into Microsoft Excel spreadsheets.

During the latter half of July, security researchers warned of a previously undisclosed vulnerability in Adobe Flash Player that was being exploited in the wild through malformed SWF files. In addition to the SWF-based drive-by download attacks, it was confirmed that Adobe Reader and Acrobat were vulnerable as well, because of the ability to embed Flash streams into PDF files.

At the end of July, Adobe released security updates that addressed this vulnerability, identified as CVE-2009-1862, for its Flash Player, AIR, Reader and Acrobat products. Nevertheless, it's well known by the security industry and cybercriminals alike that end users and even many corporate ones don't patch in a timely manner.

In such cases, antivirus solutions are the only method of protection and most of them have added detection for the malicious SWF and PDF files. However, security researchers from antivirus vendor Sophos warn that, in order to counter AV protection, malware distributors have switched to using Excel files, which also support embedded Flash.

"It was only a matter of time before the AVs caught up and started blocking suspicious PDFs and so the game has moved onto finding other compound files capable of embedding and invoking Flash objects. Microsofts OLE2 compound document format is well suited to this scenario and is being actively exploited," they explain.

The sample file looks like an empty spreadsheet when opened in Excel, except it contains two Flash objects hidden in one of the cells. "The two embedded Flash objects are detected as Troj/SWFExp-M and Troj/SWFExp-N and are of the same nature as used in the PDF of recent past," is noted in the Sophos alert.

Peter Szabo, senior virus researcher at SophosLabs Australia, advises that this attack is likely to be adapted to PowerPoint and Word documents too. All users are strongly encouraged to upgrade to the latest version of Flash Player.

TELL US WHAT YOU THINK:

2,788 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Adobe Reader and Acrobat Critical Updates Available

Important Updates Released for Adobe Flash Player and Adobe AIR

Adobe Criticized for Shipping Insecure Reader Version

Adobe Flash Player Zero-Day Vulnerability Exploited in the Wild

Web Exploit Kit Targets 0-Day Microsoft DirectShow Vulnerability

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM