• On GameSpot: Wii Fit tells 10-year-old she's fat

June 20, 2006 12:53 PM PDT

Second zero-day Excel flaw emerges

Last modified: June 20, 2006 3:39 PM PDT

Attack code for a new security hole in Excel has surfaced on the Internet, just as Microsoft is scrambling to respond to a separate bug in the spreadsheet program.

The latest vulnerability could cause Excel to crash after a malicious file is opened, according to an alert Symantec sent to customers on Monday. The security company also said there was a risk that an intruder could commandeer a PC. "Attackers may also be able to execute arbitrary code?but this has not been confirmed," it said.

The security hole exists because Excel fails to properly check user-supplied input before copying it to an insufficiently sized memory buffer, Symantec said. Excel 2003 and Excel XP are vulnerable, and other versions may also be affected, Symantec said.

Security monitoring company Secunia deems the issue "highly critical," one notch below its most severe ranking, according to an alert it published on Tuesday.

Sample computer code that exploits the flaw is publicly available on the Net. However, Secunia said it is not aware of any current attacks using the security hole.

Microsoft is looking into the issue, a company representative said in a statement Tuesday. "Based on our investigation, the issue is a new vulnerability in Microsoft Windows that may be exploited when clicking on a hyperlink with Office documents," the representative said. Microsoft is not aware of any attacks that exploit this flaw, he added.

The latest Excel vulnerability comes just as Microsoft is grappling with another yet-to-be-patched bug in the spreadsheet application. That flaw, disclosed late last week, could give an attacker full control over a vulnerable PC and has been exploited in at least one targeted cyberattack, Microsoft has said.

To exploit either one of the new flaws, an attacker would craft a malicious Excel file and host that file on a Web site, send it via e-mail, or otherwise provide it to the intended victim. The attempt can be successful only if the file is opened on a vulnerable PC.

Both vulnerabilities come on the heels of Microsoft's "Patch Tuesday" batch of security updates. Last week, Microsoft released 12 patches that addressed 21 vulnerabilities in various products, including Office applications. The company has said it is working on a patch for the first new Excel flaw.

Some experts believe the timing of the new exploits is no coincidence, as miscreants will have a month until patches are available. Microsoft typically does not release fixes outside of its monthly patching cycle for such flaws, these experts said.

On Monday, Microsoft posted tips for users to respond to the first Excel flaw, which affects all versions of the software, including those for Apple Computer's Mac OS. Microsoft suggests caution when opening Excel files. It also recommends blocking such files when they arrive as e-mail attachments or changing PC settings so spreadsheets can't be opened from the Outlook e-mail client or the Web.

For Excel 2003, Microsoft recommends that people prevent the application from running in "repair mode" by modifying some settings in the Windows Registry. The flaw is exploited in that special mode, Microsoft said in a security advisory on the issue.

See more CNET content tagged:
Microsoft Excel, security hole, Microsoft Excel 2003, flaw, vulnerability

Add a Comment (Log in or register) 10 comments
Isn't This A Flaw In The OS?
by maxwis June 20, 2006 1:36 PM PDT
How is it than an application program is able to compromise operating system security to this extent? If the OS cannot prevent this condition, then isn't any application, not just Excel, a potential vector for infiltration?

Also, will 3rd party security tools like ZoneAlarm and Norton trap and prevent the Excel infiltration?
Reply to this comment View all 4 replies
Here's The Fix For These Hacks:
by kamwmail-cnet1 June 20, 2006 1:38 PM PDT
Download OpenOffice 2.0 from http://www.openoffice.org and allow it to be associated with Word, Excel and PowerPoint files. When you click on the file from the download, Microsoft malware will not active, instead OpenOffice will activate.

Best of all, OpenOffice is a FREE LICENSE. And I had tested OpenOffice, it's idiot simple for a Microsoft Office user to use the similar OpenOffice interface.
Reply to this comment
Here's The Fix For These Hacks:
by kamwmail-cnet1 June 20, 2006 1:39 PM PDT
Download OpenOffice 2.0 from http://www.openoffice.org and allow it to be associated with Word, Excel and PowerPoint files. When you click on the file from the download, Microsoft malware will not active, instead OpenOffice will activate.

Best of all, OpenOffice is a FREE LICENSE. And I had tested OpenOffice, it's extremely simple for a Microsoft Office user to use the similar OpenOffice interface.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from CNET News sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right