Microsoft Excel zero-day vulnerability confirmed

Security

In what is turning out to be the most serious security year on record, yet another zero-day vulnerability has been discovered in a Microsoft Office product. This time a hole in the Excel spreadsheet has been found, with at least one attack confirmed by Microsoft.

Just one month ago, a hole was discovered in Microsoft Word, that enabled attackers to gain control of a computer through an infected Word email attachment. No sooner has that problem been patched than a new vulnerability in Excel has surfaced, which allows attackers to gain control of a computer when a user opens a malicious Excel attachment called okN.xls which infects the computer with a Trojan horse.

In a post to a company blog, Microsoft operations manager Mike Reavey said the company had received a single report from a customer being impacted by an attack using a new vulnerability in Microsoft Excel.

"Here's what we know: In order for this attack to be carried out, a user must first open a malicious Excel document that is sent as an email attachment or otherwise provided to them by an attacker.  (note that opening it out of email will prompt you to be careful about opening the attachment) So remember to be very careful opening unsolicited attachments from both known and unknown sources," said Reavey.

The new Microsoft Office zero-day Excel vulnerability is so similar to the previous Word vulnerability that some experts believe that the two attacks are connected in an organised criminal conspiracy. With the Word vulnerability, users had to wait weeks until Patch Tuesday to get a fix. It is not clear whether Microsoft will make users wait that long again to receive a patch for the new Office product hole.

If 2006 is going to be remembered for anything apart from the year Microsoft entered the security space, it could very well be the year that email users had to be careful about opening any emails at all. Flaws in non-executable document attachments and vulnerabilities caused by JavaScript code are rapidly combining to make email an unsafe method to exchange information.

Tags:

Please enable JavaScript in your browser to post your comment!

SPONSORED PRESS RELEASES

Websense Security Labs Reports ‘User Trust’ Targeted Attacks; Over 1 in 10 ‘Top Search’ Results Categorised as Malware; Increased Focus on Web 2.0
Websense, Inc. today revealed the findings from its bi-annual research report: Websense Security Labs, State of Internet Security, Q3-Q4 2009.

Featured IT jobs

A varied DBA role that involves multitasking in a dynamic software development environment dealing with challenging customer needs on a daily basis.
Skills Tags:   Linux  Oracle  UAT
A position has just become available for experienced Program/Project Manager to join a large organisation on a major Data Centre upgrade....
Skills Tags:   SAP
URGENT! Experienced BDM needed for senior sales role in Melbourne - must have ITSM consultancy sales experience.
Skills Tags:   C  Development  EDI  IT
CRITICAL INCIDENT COORDINATOR - 24 x 7 shifts - 3 month CONTRACT ONLY...
Skills Tags:   Excel  IT  ITIL  Management  Reporting

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases