ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Cyber attack targets unpatched Excel flaw

Joris Evers CNET News.com

Published: 19 Jun 2006 09:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new, yet-to-be-patched security vulnerability in Microsoft's Excel has been exploited in at least one targeted cyber attack, experts warned on Friday.

A malicious Excel document is sent as an email attachment or otherwise delivered by the attacker to the intended victim, Microsoft said in a posting to its Security Response Center site. The software giant said it has received one report from a customer who had been hit by such a problem.

A Microsoft representative wrote: "In order for this attack to be carried out, a user must first open a malicious Excel document. So remember to be very careful opening unsolicited attachments from both known and unknown sources."

Samples of malicious Excel files called "okN.xls" have been found, Symantec said in an advisory. The malicious spreadsheet file contains a Trojan horse, called "Mdropper.J", and program called "Booli.A" that can download more malicious files to an infected PC, the security company said.

Symantec said: "Attackers are actively exploiting this vulnerability in targeted attacks." The issue appears to affect all versions of Excel, including Excel 2003 and Excel 2000. If the attempt is successful, the intruder will gain full control over the targeted computer, the company said.

Word of the outbreak and of the new flaw comes just days after Microsoft released 12 security bulletins with fixes for 21 vulnerabilities in several of its products, including Office. Some experts believe the timing of the new attack is no coincidence.

Scott Carpenter, director of Security Labs at Secure Elements, said in a statement: "In recent similar attacks, Microsoft has not issued an out-of-cycle patch. The exploit's immediate release after 'Patch Tuesday' is evidently designed to take advantage of a full month before Microsoft is scheduled to patch it."

In addition, the monthly set of patches Microsoft released on Tuesday included a fix for a Word flaw that had already been used in targeted cyber attacks. Instead of issuing an out-of-cycle patch, Microsoft recommended that users be careful in opening Word documents and that they run the application in safe mode.

Microsoft has not said whether it plans to release a fix for the new Excel flaw. The software maker said it has added detection capabilities to its Windows Live Safety Center for removal of malicious software that attempts to exploit the vulnerability.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
68 out of 136 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

JavaScript / AJAX / Web 2.0 development role

I have a brand new, exciting opening in Edinburgh for a rapidly expanding software house poised to further attack the market on the back of recent ...

Credit Risk Analyst: North West 23-30K+Extensive benefits

Ability to develop profit models to analyse the relationship between risk and reward across the credit cycle My client is seeking the following ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment