Thursday, 9th September 2010
_______________________________________________________________________________________________________

30 Days & Microsoft Fails To Deliver A Security Update

It’s been almost a month when Microsoft announced a security breach in various versions of Microsoft Excel. They wrote about some details of the vulnerability but didn’t explain clearly about the solutions. Updates were promised after some research was over and it has now been more then a month since the research process is on. Someone knows when will they be releasing the update?

Software Affected

  • Microsoft Office Excel 2003 Service Pack 2.
  • Microsoft Office Excel Viewer 2003.
  • Microsoft Office Excel 2002.
  • Microsoft Office Excel 2000.
  • Microsoft Excel 2004 for Mac.

Software NOT Affected

  • Microsoft Office Excel 2007.
  • Microsoft Excel 2008 for Mac.
  • Microsoft Office Excel 2003 Service Pack 3.

How it works

The vulnerability can be exploited if an attacker uses a specially crafted Excel file with malformed header information. Successful exploitation allows execution of arbitrary code on victims computer.

Solution

Not yet released! Although as a precaution whenever you get some Excel file as an attachment do confirm about the attachment with the sender before opening the file. And do keep a check on this page to see when a patch is released.

More: Read about some more highly critical bugs found in our archives.

Tags:

Leave a Reply

Please fill the required box or you can’t comment at all. Please use kind words. Your e-mail address will not be published.

Gravatar is supported.

You can use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>