GCN Tech Blog

By GCN Staff

Blog archive

Microsoft Excel attack in the offing

Microsoft today confirmed a new hole in its widely used Excel spreadsheet program.

Security firm Secunia has reportedly been able to pinpoint the flaw on an updated Windows XP Service Pack 2 system with Microsoft Excel 2003 SP2. According to the firm, "This vulnerability is a so-called zero-day and is already being actively exploited....Don't open untrusted Excel documents."

Windows 95, Windows 98, Windows Me, Windows NT and Windows 2000 machines running Excel may also be at risk.

In Microsoft's Security Response Center blog, Microsoft Operations Manager Mike Reavey wrote, "In order for this attack to be carried out, a user must first open a malicious Excel document that is sent as an email attachment or otherwise provided to them by an attacker."

Symantec Corp. was reportedly first on the scene to spot the attack. In it, a Trojan horse called Trojan.Mdropper.j is transmitted in an Excel e-mail attachment with a name like "okN.xls."

eWeek describes the subsequent attack this way:

"When the Trojan is executed, it exploits the Excel flaw to drop and execute a second piece of malware called Downloader.Booli.A. It then silently closes Microsoft Excel, much like that way the Microsoft Word attack worked.

Downloader.Booli.A attempts to run Internet Explorer and inject its code into the browser to bypass firewalls. It then connects to a remote Web site hosted in Hong Kong to download another unknown file."


Major security companies have already added signatures to detect the attack, but users should beware.

Posted by Brad Grimes

Posted by Brad Grimes, Joab Jackson on Jun 16, 2006 at 9:39 AM


Featured

  • FCW Perspectives
    remote workers (elenabsl/Shutterstock.com)

    Post-pandemic IT leadership

    The rush to maximum telework did more than showcase the importance of IT -- it also forced them to rethink their own operations.

  • Management
    shutterstock image By enzozo; photo ID: 319763930

    Where does the TMF Board go from here?

    With a $1 billion cash infusion, relaxed repayment guidelines and a surge in proposals from federal agencies, questions have been raised about whether the board overseeing the Technology Modernization Fund has been scaled to cope with its newfound popularity.

Stay Connected