News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Windows Security
Average Rating:
Rate this article:  
Critical Security Flaw Found in Microsoft Excel Critical Security Flaw Found in Microsoft Excel
By Walaika K. Haskins
June 22, 2006 2:15PM

    Bookmark and Share
"It is bad for Microsoft to have two zero-day exploits in the wild right after their Patch Tuesday," said Rob Ayoub, an analyst at Frost & Sullivan. "They're scrambling to figure out what's going on and probably won't release a patch until their next Patch Tuesday. The timing is pretty bad."
 



Microsoft Relevant Products/Services is investigating reports of a serious security vulnerability in Excel that not only could cause the program to crash, if attacked remotely, but also could provide a way for hackers to take control of a system Relevant Products/Services.

The disclosure of the new flaw comes as Microsoft attempts to develop a patch to fix another security hole revealed in Excel late last week.

The Microsoft Security Response (MSR) team reported on its blog this week that the vulnerability is the result of a faulty component in Windows Relevant Products/Services that handles system operations involving hyperlinks.

The blog posts downplayed the significance of the vulnerability. "This [is] proof-of-concept code and not an attack," wrote Christopher Budd, an MSR team member. "We are not aware of any attacks based on this code."

However, despite the absence of ready-made hacker software that can take advantage of the flaw, Secunia, a security-monitoring company, has given the bug a rating of "highly critical."

Security Issues

According to Secunia, the flaw is caused from what is called a "boundary error" in an Excel-related Windows file named "hlink.dll."

MSR researchers said that any attempt to exploit the flaw would necessitate convincing a user to open a specially crafted Excel document. Then the user would have to find and click on a specifically designed link in that document.

"We have not found any way to attempt to exploit this vulnerability that involves simply opening a document: A user must locate [and] click [on] a hyperlink in the document," Budd wrote.

Secunia claims to have confirmed the existence of the vulnerability on a fully patched Windows XP system running Excel 2003. Other affected operating systems, according to Secunia, include Windows Server 2003 and Windows 2000.

Microsoft is recommending that people "only accept and open files from trusted sources."

Bad Timing

The flaw could not have been disclosed at a worse time for Microsoft because the company released its latest monthly set of patches just last week. Typically, the software maker does not issue fixes outside of "Patch Tuesday" releases, which means hackers will have one month to come up with malicious software specifically designed to take advantage of this flaw.

"It is bad for Microsoft to have two zero-day exploits in the wild right after their Patch Tuesday," said Rob Ayoub, an analyst at Frost & Sullivan. "They're scrambling to figure out what's going on and probably won't release a patch until their next Patch Tuesday. The timing is pretty bad."

Ayoub said that, other than causing some damage in terms of the public perception, the flaw will not pose too much of a threat. Because hackers have to get users to click on a specially designed link, it will be hard for miscreants to launch any sort of widespread attack, he explained.

"It looks like this is more difficult to execute and won't propagate without user intervention," Ayoub said. "It is bad? Yes, but it's probably worse for Microsoft's publicity than it might actually be dangerous."
 

Tell Us What You Think
Your Comment:



Advertisement


 Windows Security
1.   Patch Tuesday Will Tie MS Record
2.   Free Add-On Software for Windows 7
3.   Microsoft Will Issue Patch for IE6
4.   Germany Warns Users Against IE
5.   Oracle, Adobe Patch Vulnerabilities


advertisement
Oracle, Adobe Patch VulnerabilitiesOracle, Adobe Patch Vulnerabilities
Microsoft's Patch Tuesday very light.
Average Rating:
Free Add-On Software for Windows 7Free Add-On Software for Windows 7
Find new tools to enhance functionality.
Average Rating:
Microsoft Will Issue Patch for IE6Microsoft Will Issue Patch for IE6
Upgrading to IE8 is still a good idea.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.