This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Excel 0-Day exploit report

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1420
Last Updated: 2006-06-16 06:02:01 UTC
"Microsoft has received a report of a new 0-day vulnerability involving Excel. They are currently investigating this issue and will issue more information on workarounds as it becomes available. They are currently blogging about it at http://blogs.technet.com/msrc/archive/2006/06/16/436174.aspx so check that site for more information as it becomes available.
In the meantime, we continue to recommend the same defenses we recommended with the Word 0-day from last month located at http://isc.sans.org/diary.php?storyid=1347 . These very general best practices should help alleviate the danger until Microsoft releases a patch or more specific workarounds."

Also:
- http://secunia.com/advisories/20686/
Release Date: 2006-06-16
Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Unpatched…

:ph34r:
Update… http://isc.sans.org/diary.php?storyid=1420
Last Updated: 2006-06-16 13:17:26 UTC
"Update - We've recieved reports… that Symantec is detecting this attack. According to the mdropper.j description, mdropper.j is used to drop Downloader.Booli.A which then exploits Excel. The Symantec website also reports …
'…Downloader.Booli.A* may arrive on the compromised computer, dropped by Trojan.Mdropper.J **, with the following name: %System%\svc.exe
Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
…When Downloader.Booli.A is executed, it performs the following actions:
1. Attempts to run Internet Explorer and inject its code into Internet Explorer to potentially bypass firewalls.
2. Attempts to download a file from the following location: [http://]210.6.90.153:7890/svcho[REMOVED]
Note: At the time of writing the remote file was not available.
3. Saves the file as the following and if the download was successful, executes the file: c:\temp.exe
4. Creates an empty file before exiting: c:\bool.ini …'

We'll pass on more information as we receive it."

* http://securityresponse.symantec.com/avcen…oli.a.html?Open

** http://securityresponse.symantec.com/avcen…per.j.html?Open

:ph34r:
FYI…

- http://isc.sans.org/diary.php?storyid=1426
Last Updated: 2006-06-19 11:20:14 UTC
"…Update: A perl script was published on Milw0rm which claims to be a PoC exploit for this vulnerability. It creates a spreadsheet including a very long URL. Once the user clicks on the URL, Excel will crash. We have not confirmed that code execution is possible with this bug or if the same flaw was used in the recent 0-day exploits…

…The first and only defense is - defense in depth.

> Do NOT rely solely on antivirus.
> Do NOT rely solely on filtering by extension.
> Do NOT open Excel files that appear unsolicited in your mailbox.
> No single tool or measure is sufficient.

I am hoping that the point is getting accross, do not rely on traditional defensive measures, it is quite likely they will prove inadequate against a custom made targeted trojan built just to penetrate your infrastructure. Particularly using an undisclosed vulnerability. No signature based tool can help you in this case."

:ph34r:
FYI…

MS Office Long Link Buffer Overflow Vuln
- http://secunia.com/advisories/20748/
Release Date: 2006-06-20
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software:
Microsoft Excel 2000, Microsoft Excel 2002, Microsoft Excel 2003, Microsoft Excel Viewer 2003, Microsoft Office 2000, Microsoft Office 2003 Professional Edition, Microsoft Office 2003 Small Business Edition, Microsoft Office 2003 Standard Edition, Microsoft Office 2003 Student and Teacher Edition, Microsoft Office XP …
…The vulnerability is caused due to a boundary error in hlink.dll within the handling of Hyperlinks in e.g. Excel documents. This can be exploited to cause a stack-based buffer overflow by tricking a user into clicking a specially crafted Hyperlink in a malicious Excel document. Successful exploitation allows execution of arbitrary code. The vulnerability has been confirmed in Microsoft Excel 2003 SP2 (fully updated). Other versions and Office products may also be affected.
NOTE: Secunia is currently not aware of this vulnerability being actively exploited and working exploit code is not currently publicly available. However, the vulnerability is quite simple to exploit and it is therefore likely that exploit code is published soon.
Solution:
Do not open untrusted Microsoft Office documents.
Do not follow links in Microsoft Office documents…"

- http://isc.sans.org/diary.php?storyid=1432
Last Updated: 2006-06-20 17:34:08 UTC
"…the organizations that really need to be concerned about 0day are the ones responsible for protecting military/government assets, financial institutions, and critical infrastructure agencies. Since you know 0day exists and if you are a target, what are you doing to protect yourself? How do you protect against, detect, and respond to unknown vulnerabilities?
For the rest of the folks out there (small/medium businesses, hobbyists)… Should you worry about 0day? Usually not, but if you have all the other critical security components in place then go ahead… There is also a good list of commercial products for Windows… here: http://isc.sans.org/diary.php?storyid=635
In summary, you should expect 0day to be alive and well for your favorite operating systems, daemons, and applications. And if it concerns you, then do something about it instead of waiting to get smacked with it later. You will sleep better at night and not be frustrated at your favorite software vendor when they take 6+ months to patch simple little vulnerabilities."

Suggested reads:
- http://isc.sans.org/diary.php?storyid=635
- Data Execution Protection (DEP): http://support.microsoft.com/kb/875352

.
FYI…

- http://blogs.technet.com/msrc/archive/2006/06/20/437826.aspx
June 20, 2006 11:17 PM
"I wanted to give you some information about the recent posting of proof of concept PERL script that claims to demonstrate a vulnerability in Excel's processing of long links…it actually is a vulnerability in hlink.dll which is a Windows component that handles operations involving hyperlinks. Any attempt to exploit this vulnerability would require convincing a user to open a specially-crafted Excel document. The user would then also have to locate and click on a specially-crafted long link in that document. We have not found any way to attempt to exploit this vulnerability that involves simply opening a document: a user must locate a click a hyperlink in the document. As a reminder, it’s important to make sure that you only accept and open files from a trusted source, as well as be careful what websites you visit…"

:blink:
Also:

Vulnerability Note VU#394444
Microsoft Hyperlink Object Library stack buffer overflow

- http://www.kb.cert.org/vuls/id/394444
Last Updated: 06/21/2006
"…The Problem
There is a stack-based buffer overflow in the Microsoft Hyperlink Object Library. The overflow may be triggered by clicking a specially crafted hyperlink. Note that any program that links to the HLINK.DLL library may be vulnerable, including Microsoft Office applications. Exploit code for this vulnerability is publicly available…
Solution
There is currently no patch or update to correct this problem. Until a solution is available, refer to the workaround below.
- Do not follow unsolicited hyperlinks
- Do not click on unsolicited links received in email or embedded in Office documents. Exploitation of this vulnerability requires a user to click a specially crafted link. By only accessing hyperlinks from known and trusted sources, the chances of exploitation are reduced…"

.
FYI…

…Third Zero-Day Excel Flaw
- http://www.techweb.com/article/printableAr…_section=700028
June 22, 2006

…Excel 'Shockwave Flash Object' Lets Remote Users Execute Code…
- http://www.securitytracker.com/alerts/2006/Jun/1016344.html
CVE Reference: CVE-2006-3014 …
Date: Jun 20 2006
Impact: Execution of arbitrary code via network, User access via network
Vendor Confirmed: Yes
Description: A vulnerability was reported in Microsoft Excel. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create an Excel file that includes a malicious Flash file embedded using the Excel 'Shockwave Flash Object' function. When the target user opens the Excel file, the Flash code will execute automatically without user interaction. The code will run with the privileges of the target user. The vendor was notified on May 3, 2006…
Impact: A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution: No solution was available at the time of this entry.
Microsoft indicates that customers can set ActiveX control kill bits to prevent the observed behavior. Information on setting kill bits is available at: http://support.microsoft.com/kb/240797/EN-US/ …"

:ph34r: :ph34r: :ph34r:
FYI…

Excel Issue Scorecard
- http://isc.sans.org/diary.php?compare=1&storyid=1444
Last Updated: 2006-06-25 01:00:02 UTC
"…This information comes from Microsoft, Mitre, and vigilant readers sending in tips…

CVE-2006-3059 aka "Excel Repair Mode" http://www.microsoft.com/technet/security/…ory/921365.mspx
Exploited by: Mdropper.G, Booli.A, Flux.E, Booli.B

CVE-2006-3086 aka "Long Hyperlink" http://blogs.technet.com/msrc/archive/2006/06/20/437826.aspx
Exploited by: Urxcel.A, and three known public exploit code examples

CVE-2006-3014 aka "Shockwave vulnerability"
Exploited by proof of concept code Flemex.A
The workaround is a killbit …"

(Still, no patches have been released for -any- of them.)

.
FYI…

- http://secunia.com/advisories/20686/
Release Date: 2006-06-16
Last Update: 2006-07-12
Critical: Extremely critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch…
NOTE: This vulnerability is a so-called 0-day and is already being actively exploited.
Successful exploitation of the vulnerabilities allows execution of arbitrary code…
Solution: Apply patches…
Advisory:
MS06-037 (KB917285): http://www.microsoft.com/technet/security/…n/MS06-037.mspx …"

:ph34r: