Microsoft Confirmed Excel Vulnerability Threatens Windows and Mac Users
Just yesterday we were reporting on a critical security vulnerability that plagues Adobe Reader and Adobe Acrobat running on Windows and Mac, and now there is more bad news for Windows fans and Mackies alike: there is a zero-day vulnerability in Microsoft’s Excel that is actively being exploited by people with malicious intent. As a matter of fact, a Trojan created by virus writers is already making its rounds, targeting several versions of Excel.
“Microsoft is investigating new public reports of a vulnerability in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability. We are actively working with partners in our Microsoft Active Protections Program (MAPP) and our Microsoft Security Response Alliance (MSRA) program to provide information that they can use to provide broader protections to customers,” said Microsoft.
The platforms affected are: Microsoft Office 2000, Microsoft Office 2002, Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2004 for Mac, Microsoft Office 2008 for Mac, and Open XML File Format Converter for Mac. Microsoft said that once the investigation has taken its course they will asses the proper course of action and take it. This means that Microsoft might issue either a service pack or a security update, even an out-of-date one (which is a rare occurrence with the Redmond software developer). Customer security and satisfaction is the main priority here, and a fix will be made available according to the customer’s needs.
The only upside is that an automated attack is not possible; in order to get infected, the user must download and open a maliciously crafted Excel document. When that document is opened, two files are dropped on the system: a valid Excel document and a malicious binary. The end result is that you unknowingly execute a Trojan downloader, which can be used to steal your confidential data (record keystrokes for example).
Tags: Microsoft, Excel, Trojan
“Microsoft is investigating new public reports of a vulnerability in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability. We are actively working with partners in our Microsoft Active Protections Program (MAPP) and our Microsoft Security Response Alliance (MSRA) program to provide information that they can use to provide broader protections to customers,” said Microsoft.
Advertising
The platforms affected are: Microsoft Office 2000, Microsoft Office 2002, Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2004 for Mac, Microsoft Office 2008 for Mac, and Open XML File Format Converter for Mac. Microsoft said that once the investigation has taken its course they will asses the proper course of action and take it. This means that Microsoft might issue either a service pack or a security update, even an out-of-date one (which is a rare occurrence with the Redmond software developer). Customer security and satisfaction is the main priority here, and a fix will be made available according to the customer’s needs.
The only upside is that an automated attack is not possible; in order to get infected, the user must download and open a maliciously crafted Excel document. When that document is opened, two files are dropped on the system: a valid Excel document and a malicious binary. The end result is that you unknowingly execute a Trojan downloader, which can be used to steal your confidential data (record keystrokes for example).
Tags: Microsoft, Excel, Trojan
I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 10 Feb 2012
With the release of Wolfram|Alpha Pro, the team behind the popular computational knowledge engine took a very big step forwardBy George Norman on 10 Feb 2012
Microsoft has just announced that this February, as part of the Patch Tuesday program, it will roll out a grand total of 9 security bulletins to all customers all over the world.Related News
By George Norman on 23 Dec 2011
Redmond-based software giant Microsoft has said goodbye to its keynote presentation and booth at the Consumer Electronics Show (CES), the technology trade show held each January in the Las Vegas Convention Center. By George Norman on 02 Dec 2011
With 2011 quickly drawing to an end, the team behind Microsoft’s Bing search engine made public a list of the most popular searches on Bing in 2011. The list includes the most searched people, the most searched news stories, the most searched sports starsBy George Norman on 21 Sep 2011
One million students from low-income families in the US will have access to software, hardware, and discounted broadband internet service courtesy of Redmond-based software giant Microsoft. By George Norman on 27 Oct 2011
It is true that the mouse is one of the most used peripheral and it is just as true that if you want to get things done and get them done fast, using keyboard shortcuts is a lot more efficient than clicking.Advertising
Hot Software Updates
Top Downloads
2.
Opera5.
Trillian8.
AIM9.
Skype10.
Ad-Aware12.
Nero13.
Google Earth14.
Picasa15.
Winamp16.
iTunes17.
RealPlayer18.
uTorrent19.
eMule20.
WinRAR21.
BitComet22.
WinZip23.
Shareaza24.
CCleaner25.
Recuva26.
Tweak UI27.
CuteFTP Home29.
Adobe Reader30.
NewsPiperBecome A Fan!
Link To Us!
Microsoft Confirmed Excel Vulnerability Threatens Windows and Mac Users
HTML Linking Code
HTML Linking Code





