The Food Blog for Hungry Bachelors
Powered by MaxBlogPress  

They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety.
-Benjamin Franklin

gma-resign
Your ad here

« One Hurdle for One Voice: Cynical Pinoy
» Impeachment 2006: Born Dead

Tech Security

MS Excel Hit with Security Holes in a Month

06.24.06 | Comment?


If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

Probably the most used application in the Microsoft Office suite, Excel has been hit with three security holes this month.

Microsoft has published a Security Advisory, warning Excel users of an Excel vulnerability that allows remote code execution. Affected users should check the suggested workarounds, since this vulnerabilty is already being exploited: see here for a representative malware.

Then, it was found out that entering a very long URL in an Excel cell will cause a buffer overflow. Microsoft has not published any advisory regarding this vulnerability. Full Disclosure has the details here. Here is a description of a malware that exploits this vulnerability.

And, lastly, another security hole in Excel with regards to Shockwave Flash Objects embedded in a spreadsheet has been discovered. This Flash file may contain malicious JavaScript code, and this file is opened when an Excel workbook where this Flash file is embedded is opened. Full Disclosure has the following details. Here is the malware description that exploits this problem.

As usual, be careful when you have received an Excel file as an attachment to an unsolicited email, or email coming from unknown or untrusted sources. Take note that Microsoft has not yet released patches for the said vulnerabilities.

Like my article? Leave a tip! Or, treat me to a cup of coffee!

Visit the AWBHoldings.com Online Store!


If your comment is eaten by Akismet or just went somewhere else, please let me know. You can either leave a message at the chat box at the lower left, or via the contact page. Thanks!

RSS feed | Trackback URI

Comments »

No comments yet.

Name (required)
E-mail (required - never shown publicly)
URI
Subscribe to comments via email
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

Comments will be sent to the moderation queue.


« One Hurdle for One Voice: Cynical Pinoy
» Impeachment 2006: Born Dead