The hole is dubbed the "Russian New Year" exploitation
Published:
14 January 1999 y., Thursday
Microsoft Corp._s Excel spreadsheet software has a vulnerability that lets hackers run certain types of
executables that can give them access to a PC user_s files, Internet security firm Finjan Inc. said yesterday. The hole is dubbed the "Russian New Year" exploitation, Finjan said in a statement from its offices in San Jose, Calif. The company said the new form of mobile-code attack "clearly illustrates the latent security threats on the Internet and the importance of inspecting any type of code that is downloaded onto your personal computer." John Duncan, product manager for Microsoft_s Office suite -- which includes Excel -- said information regarding the problem, along with a patch that plugged the vulnerability, was posted on Microsoft_s Web site Dec.10. The hacker backdoor is a legitimate Excel function, dubbed CALL, that allows executables to be run from a worksheet, Microsoft said. But if that executable, delivered via E-mail or from a Web site, is of a
malicious nature, "a worksheet containing this function could represent a security risk to customers," according to a Microsoft security bulletin also dated Dec. 10.
Finjan said Office 97 and Excel 97 users should apply Microsoft_s patch to disable the CALL function. But it added that Office 95 and Excel 95 "do not appear to have a patch to eliminate this CALL function nor do non-English language versions of Office 97 or Excel 97 have a solution."
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.
The most popular articles
Software company announced new structure_ of it_s business.
more »
Unisys Corporation (NYSE: UIS) announced enhancements to its Baggage Reconciliation System (BRS) featuring more detailed information about baggage handling requirements for incoming flights, real-time monitoring and alerts of service level agreements (SLAs), and a mobile app to provide passengers with live updates on when and where to collect their bags.
more »
Samsung doubled its share of the tablet PC market in the last three months of 2012, research firm IDC has said.
more »
Facebook boss Mark Zuckerberg has strongly denied the social network is planning to release its own phone.
more »
The OnLive gaming service is to be made available to Google TV users, following a deal with electronics firm LG. One of a handful of firms making hardware for Google TV. LG's G2 series sets have Google's TV service built in.
more »
Blackberry has become the latest smartphone to offer free wi-fi calls to users via its own software. Research In Motion (RIM) has added the facility to its Blackberry Messenger (BBM) app, which already offered an alternative to text messages.
more »
We are delighted to announce that on 26th of January SafeNet Sentinel Cloud was awarded the SiiA 2012 Best Digital Rights Management Solution!
more »
The Spanish government has approved tough new legislation which could see websites deemed to be trading in pirated material blocked within ten days.
more »
The Los Angeles World Airports (LAWA), which oversees airport operations for the city of Los Angeles, has awarded a contract modification to Unisys (NYSE: UIS) to upgrade its access control and alarm monitoring system, used to identify the 45,000 airport employees, contractors, police and others who work at the organization’s three airports.
more »
Unisys Corporation (NYSE: UIS) today announced Version 2 of its Unisys Secure Private Cloud Solution, the company’s flagship cloud solution for clients’ and cloud service providers’ data centers.
more »
An American blogger has discovered three fake Apple stores operating in Kunming city, China.
more »