eWeek Microsoft Watch
Advertisement
Advertisement
February 7, 2007 5:44 PM

Excel Exploit Emerges



Joe Wilcox
Joe Wilcox

Symantec's Security Response Weblog reports the company has received malicious code capable of exploiting Microsoft's newest zero-day vulnerability.

The exploit drops a Trojan and opens a back door on the infected system that "may enable an attacker to gain remote access to your computer," wrote Amado Hidalgo in the blog post.

The malicious code appears to exploit "a bug on MSO.DLL," which is an Office shared library. While Office applications could be vulnerable, Symantec has only seen code that exploits Excel. "Fully patched versions of Office 2000, XP, and 2003 appear to be vulnerable to this exploit," Hidalgo wrote.

Security Snapshoft

On Friday, Microsoft issued a security bulletin for the zero-day flaw, which is the fifth since December.

Symantec's post somewhat raises the urgency around the flaw, because the one exploit can drop a back-door Trojan onto an infected system. Trojans of this kind allow remote download of software onto an infected computer.

Microsoft isn't the only software vendor struggling to combat vulnerabilities. According to the U.S. Department of Homeland Security's National Vulnerability Database there were 6,604 software vulnerabilities in 2006, up from 4,869 vulnerabilities in 2005 and 2,357 and 1,257 in, respectively, 2004 and 2003.

Vulnerability Impact

Vulnerabilities and exploitable flaws are up for just about every software category. Additionally, risks posed by vulnerabilities are increasing in most categories.

However, incidents of unauthorized access have so far declined in 2006 compared with 2005. The data isn't final and is likely to change over the next month, which could reverse the trend.

The government database did not immediately provide access to zero-day vulnerabilities.

Create, Communicate, Collaborate with IT Professionals at Ziff Davis Enterprise IT Link.

TrackBack

TrackBack

http://www.microsoft-watch.com/cgi-bin/mte/mt-tb.cgi/10263

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Microsoft Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise Inc. All Rights Reserved. Microsoft Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise