Exclusive Deal While supplies last, save 40% off over 40 iPhone 5 and iPhone 4/4S cases and chargers as well as Samsung S III cases at Kensington.com. Use coupon code 'SAVE40%' at checkout to receive this exclusive discount.      
toggle

AAPL Stock: 445.15 ( + 3.01 )

http://www.macnn.com/articles/07/02/05/excel.zero.day.attack/

MS warns of Excel 'zero-day' attack

updated 07:20 pm EST, Mon February 5, 2007

 

Excel 'zero-day' attack


Microsoft last week began warning users of new “zero-day” attacks using a vulnerability in Microsoft Office 2004 for Mac as well as Microsoft Office 2000, Microsoft Office XP, and Microsoft Office 2003. Specifically, the attack exploits a flaw Excel spreadsheet component of the business software suite and is rated as "extremely critical" by security firm Secunia, but Microsoft on Friday said that users are vulnerable if they open a any malicious Office file, indicating it may affect other components as well. "While we are currently only aware that Excel is the current attack vector, other Office applications are potentially vulnerable," the company said in a Microsoft Security Advisory posted to its website. Ironically, the warning comes days after Microsoft chairman Bill Gates attacked Mac security.

Security firm Secunia noted that the vulnerability is caused due to an unspecified error when handling strings and can be exploited to cause a memory corruption and that warned that successful exploitation allows execution of arbitary code, resulted in a compromised user system.

"As a best practice, users should always exercise extreme caution when opening unsolicited attachments from both known and unknown sources. Microsoft has added detection to the Windows Live OneCare safety scanner for up-to-date removal of malicious software that attempts to exploit this vulnerability," Microsoft said in its security advisory.

The company said it would provide free tech support to customers who believe they are affected by the zero-day attacks, noting that there is no charge for support calls that are associated with security updates. A zero-day attack is one that exposes software bugs before they have been patched.

Although the world's largest software company said it is developing a security update for Office that addresses this vulnerability, it provided no time frame and could only tell users not to open files from untrusted sources.


by MacNN Staff

Post tools:

TAGS :

 software, business software
toggle

Comments

  1. iPond317

    Mac Enthusiast

    Joined: Feb 2000

    0

    hmm

    Common sense would tell you not to open files from ANY untrusted source. What f**kin' idiots!

  1. climacs

    Fresh-Faced Recruit

    Joined: Sep 2001

    0

    FUBG

    "Although the world's largest software company said it is developing a security update for Office that addresses this vulnerability, it provided no time frame and could only tell users not to open files from untrusted sources."

    I don't know about you but I think it's about time for a hissy fit from Bill Gates about all those horrible lies people are telling about insecure Microsuck software and OS's.

  1. rvhernandez

    Fresh-Faced Recruit

    Joined: Apr 2005

    0

    Bill Gates said...

    That hackers attack the Mac every day. What he left out was that they do so through M$ software flaws. What a jackhole!

  1. ClevelandAdv

    Fresh-Faced Recruit

    Joined: Jul 2004

    0

    Gates

    Billy is right - look, he has proof that the Mac is just as insecure as Windows. He proved it by providing the same security holes in his crappy Office Suite for Mac and Windows. Ha, Ha...see the Mac is not secure....see it has viruses too....see, it can be attacked.

    Bill, take your medication and stop s******* up my OS. Oh, and not only is Excel insecure, but it sucks like your other software.

    Why do the sheep in this world keep buying this junk.

  1. tony_se1

    Fresh-Faced Recruit

    Joined: Jan 2007

    0

    whatever

    Ironically, the warning comes days after Microsoft chairman Bill Gates attacked Mac security.

    Ironically, this has nothing to do with the fact that Bill Gates attacked mac security (sic). Plus its a good thing that Microsoft has acknowledged the problem and is working on it, since so many Mac users depend on office to do their work.

  1. climacs

    Fresh-Faced Recruit

    Joined: Sep 2001

    0

    re: whatever

    "Plus its a good thing that Microsoft has acknowledged the problem and is working on it, since so many Mac users depend on office to do their work."

    Yes they are working on it... and one of these days they will get around to patching it...

    "Although the world's largest software company said it is developing a security update for Office that addresses this vulnerability, it provided no time frame"

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

MaxUpgrades MaxConnect for 2006-2008 Mac Pro

Nobody outside of Cupertino's privileged bunch knows the future of the Mac Pro line for sure. Despite Apple's reluctance to tell us wh ...

Brother HL-3170CDW LED Printer

We've mentioned before that we are far from a paperless society. For now, at least, there are tasks that require a piece of paper for ...

HTC One

It is hard to overstate just how critically important the HTC One is to the Taiwanese company’s fortunes. Despite its alarming decline ...

toggle

Most Commented