Microsoft plugs Excel hole

Published: 14 January 1999 y., Thursday
Microsoft Corp._s Excel spreadsheet software has a vulnerability that lets hackers run certain types of executables that can give them access to a PC user_s files, Internet security firm Finjan Inc. said yesterday. The hole is dubbed the "Russian New Year" exploitation, Finjan said in a statement from its offices in San Jose, Calif. The company said the new form of mobile-code attack "clearly illustrates the latent security threats on the Internet and the importance of inspecting any type of code that is downloaded onto your personal computer." John Duncan, product manager for Microsoft_s Office suite -- which includes Excel -- said information regarding the problem, along with a patch that plugged the vulnerability, was posted on Microsoft_s Web site Dec.10. The hacker backdoor is a legitimate Excel function, dubbed CALL, that allows executables to be run from a worksheet, Microsoft said. But if that executable, delivered via E-mail or from a Web site, is of a malicious nature, "a worksheet containing this function could represent a security risk to customers," according to a Microsoft security bulletin also dated Dec. 10. Finjan said Office 97 and Excel 97 users should apply Microsoft_s patch to disable the CALL function. But it added that Office 95 and Excel 95 "do not appear to have a patch to eliminate this CALL function nor do non-English language versions of Office 97 or Excel 97 have a solution."
Šaltinis: Finjan
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Hewlett Packard to launch dual-screen desktop computer

Hewlett Packard is due to launch a new desktop computer in the UK, with pre-release users currently including interior designer Sophie Conran and her son Felix Conran. more »

Unisys names new CEO

Unisys Corp. the Blue Bell computer services and systems company, said it named Peter A. Altabef as president and chief executive officer, effective Jan. 1. more »

Tim Richards appointed as IBC chairman

IBC has named Tim Richards as the next chairman of its Partnership Board. He will take over from Mike Martin, who retires at the end of 2014. more »

Unisys to provide data centre support services to DISA

Unisys has won a contract to provide the US Defense Information Systems Agency (DISA) with a range of data centre support services. more »

Microsoft partners with Cisco to modernise data centres

Networking solutions giant Cisco today said it has signed a multi-year agreement with software major Microsoft to modernise data centres. more »

Cisco Positioned as a Leader in the Gartner Magic Quadrant for Wired and Wireless LAN Access Infrastructure

Cisco, a leading provider of wired and wireless network solutions, today announced it has been positioned by Gartner, Inc. in the Leader's quadrant of The 2014 Gartner Magic Quadrant for the Wired and Wireless LAN Access Infrastructure. more »

Cisco to build global InterCloud for 'Internet of Everything'

US giant Cisco Systems has announced plans to build a global InterCloud - the world's largest network of clouds - in collaboration with a set of partners. more »

Microsoft seeks Office for Android testers as it readies tablet version

Microsoft may have released a basic Office app for Android phones almost a year ago, but the company is now building a suite designed specifically for Android tablets. more »

Google Docs now allows editing of Microsoft Office files

Google Docs now offers its users with the option of editing all types of Microsoft Office. more »

Cisco buys cloud collaboration startup Assemblage

Cisco announced today that it has acquired cloud platform startup Assemblage, as the company continues its focus on enterprise collaboration. more »