This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Excel 0-day vuln

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

// Excel 0-day - http://www.microsoft.com/technet/security/…ory/968272.mspx

- http://atlas.arbor.net/briefs/index#-1301369182
Severity: High Severity
Published: Thursday, March 05, 2009 14:00
At least one, possibly two, new and previously undisclosed vulnerabilities have been discovered and are being actively exploited in targeted, selective attacks. The document drops an EXE that downloads more components from three websites: [removed], [removed], and [removed]. At least two of these websites appear to be disabled at this point. We do not know when this vulnerability will be fixed by Microsoft.
Analysis: This is a targeted, very selective attack at this point focusing on US government and specific agencies and third-parties at this point. We do not have any additional information to share at this time, we recommend concerned parties contact Microsoft, CERT/CC or US-CERT for additional details as needed.
- http://www.securityfocus.com/brief/914

SecureWorks
- http://preview.tinyurl.com/99wgn9

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-0238
CVSS v2 Base Score: 9.3 (HIGH)…
Impact Type: Provides administrator access, Allows complete confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service…
___

(Excel fix is absent from MS Security Bulletin Advance Notification - March 2009)
- http://www.informationweek.com/shared/prin…cleID=215800831
March 5, 2009 - "The vulnerability that Microsoft warned about just over a week ago affects files that use the old .xls binary format but not the newer .xlsx format… Conspicuously absent is a fix for the Excel security flaw…"

:ph34r:
Maybe interesting and maybe not, but I thought I would mention… I correspond with various agencies of the government and contractors who handle project development and purchasing. I have previously sent various "price lists" as password protected Excel spreadsheets. Recently my "password protected" versions are being refused automatically by the intended receiver. It may be in response to this 0-day vulnerability. Just my experience.