BleepingComputer.com: Microsoft Excel Vulnerability

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Microsoft Excel Vulnerability US-CERT Cyber Security Alert SA06-167A

#1 User is offline   jgweed 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 27,611
  • Joined: 11-April 04
  • Gender:Male
  • Location:Chicago, Il.

Posted 17 June 2006 - 11:57 AM

US-CERT advises today (5/16/06) that there is an unpatched Excel vulnerability that could allow a hacker to gain access to and control of a computer..."by convincing a user to open a specially crafted Excel document. The Excel document could be included as an email attachment or hosted on a web site. It may also be possible to exploit the vulnerability using Excel documents embedded in other Office documents."

Until a patch is released, the agency recommends extreme caution in opening "...unfamiliar or unexpected Excel or other Office documents, including those received as email attachments or hosted on a web site."

Regards,
John


http://www.us-cert.gov/cas/alerts/SA06-167A.html

To subscribe to the alert mailing list (which I strongly recommend):
http://www.us-cert.gov/cas/

Further information is provided at CNET news:

http://news.com.com/New+Excel+zero-day+fla..._3-6084738.html

This post has been edited by jgweed: 18 June 2006 - 11:15 AM

Whereof one cannot speak, thereof one should be silent.

#2 User is offline   Daisuke 

  • Cleaner on Duty
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 5,575
  • Joined: 01-September 04
  • Gender:Male
  • Location:Romania

Posted 20 June 2006 - 01:09 PM

And another 0-day vulnerability in Excel

Microsoft Office Long Link Buffer Overflow Vulnerability
Secunia: Highly critical
Solution Status: Unpatched

Workaround for the first 0-day vulnerability:
Microsoft Security Advisory (921365) (Vulnerability in Excel Could Allow Remote Code Execution)
Everyday is virus day. Do you know where your recovery CDs are ?
Did you create them yet ?

Posted Image

#3 User is online   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,518
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 26 June 2006 - 07:54 AM

Quote

Excel Issue Scorecard
Published: 2006-06-25,
Last Updated: 2006-06-25 01:00:02 UTC by Kevin Liston (Version: 2(click to highlight changes))

To help clearly identify the issues, exploit code and remedy related to the recently announce Excel vulnerabilities, I offer this humble correlation. This information comes from Microsoft, Mitre, and vigilant readers sending in tips...

Handler's Diary June 25th 2006
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users