02/05/2007, 7:20pm, EST
Monday, February 5th
MS warns of Excel 'zero-day' attack
Security firm Secunia noted that the vulnerability is caused due to an unspecified error when handling strings and can be exploited to cause a memory corruption and that warned that successful exploitation allows execution of arbitary code, resulted in a compromised user system.
"As a best practice, users should always exercise extreme caution when opening unsolicited attachments from both known and unknown sources. Microsoft has added detection to the Windows Live OneCare safety scanner for up-to-date removal of malicious software that attempts to exploit this vulnerability," Microsoft said in its security advisory.
The company said it would provide free tech support to customers who believe they are affected by the zero-day attacks, noting that there is no charge for support calls that are associated with security updates. A zero-day attack is one that exposes software bugs before they have been patched.
Although the world's largest software company said it is developing a security update for Office that addresses this vulnerability, it provided no time frame and could only tell users not to open files from untrusted sources.
Filed under: software
Other story tags: business software
,
, 6
,
,
,
,
,

subscribe to comments
for this article
I don't know about you but I think it's about time for a hissy fit from Bill Gates about all those horrible lies people are telling about insecure Microsuck software and OS's.
Bill, take your medication and stop screwing up my OS. Oh, and not only is Excel insecure, but it sucks like your other software.
Why do the sheep in this world keep buying this junk.
Ironically, this has nothing to do with the fact that Bill Gates attacked mac security (sic). Plus its a good thing that Microsoft has acknowledged the problem and is working on it, since so many Mac users depend on office to do their work.
Yes they are working on it... and one of these days they will get around to patching it...
"Although the world's largest software company said it is developing a security update for Office that addresses this vulnerability, it provided no time frame"