Excel Zero-Day Still Unpatched

執筆者
Ryan Naraine
Ryan Naraine
Published: Feb 12, 2008
Updated: Feb 2, 2021
3 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft has issued 11 security bulletins with patches for 17 documented software flaws. But Windows IT administrators are raising alarm bells because Microsoft hasn’t issued a fix for a critical-and already exploited-Excel vulnerability.

Microsoft originally planned to ship a dozen bulletins, but at the eleventh hour one of the “critical” advisories was yanked to address concerns about patch quality.

Microsoft officials would not say which product was affected by the missing bulletin, but it’s a general assumption in security circles that it was related to a memory corruption issue in Microsoft Excel 2004 and earlier versions.
On Jan. 15, 2008, Microsoft acknowledged the bug in a pre-patch advisory and warned that unknown attackers were using rigged .xls files to launch targeted code-execution attacks.
A spokesperson for the MSRC (Microsoft Security Response Center) confirmed for eWEEK that the Excel zero-day is still unpatched.
According to Jonathan Bitle, director of technical account management at Qualys, the missing Excel update is a “big worry.”
“Excel is such a [widely used] product by business users all over the world that it’s a big concern to leave a known vulnerability unpatched for an extended period of time. I imagine there will be an uproar from Microsoft customers,” Bitle said in an interview.
“I’m really surprised they didn’t get this [Excel] fix out the door, since it’s known that it’s been exploited in the wild,” he added.
However, Bitle said Windows administrators almost universally prefer a fully tested, high-quality update instead of a patch that causes applications to break or doesn’t fix the underlying vulnerability.
“Anytime there’s a potential for a company to have a false sense of security, I think that’s worse than leaving it unpatched. The first person to figure out that the patch doesn’t work will probably be someone with malicious intent. It’s good to err on the side of caution when it comes to patch quality,” Bitle said.

Click here to read more about zero-day attacks against Microsoft Excel.

In all, the February Patch Tuesday batch includes six “critical” and five “important” bulletins and provides cover for serious code execution holes in Internet Explorer, Microsoft Word, Microsoft Office, OLE automation, Microsoft Publisher and the WebDAV (Web-based Distributed Authoring and Versioning) Mini-Redirector. The cumulative IE update fixes a total of four vulnerabilities and is rated critical (remote code execution) for all supported versions of the browser, including the newest Internet Explorer 7 on Windows Vista.

Most of the “critical” updates address flaws in widely deployed products. For example, the Microsoft Word and Microsoft Publisher applications, which fall under the Office umbrella, both get a major security refresh to cover multiple vulnerabilities.

“While the batch of critical vulnerabilities all require some sort of user interaction to exploit, the interaction can be as simple as visiting a trusted Web site that has first been exploited by an attacker,” said Ben Greenbaum, senior research manager for Symantec Security Response.
Greenbaum said the client-side bugs can be exploited to distribute malware through trusted sites, e-mail attachments or links embedded in instant messaging conversations.
“These vulnerabilities underscore the importance of having a full security suite to protect consumers and enterprises from being exploited, since they can no longer only rely on traditional best practices alone, such as avoiding unknown or unexpected e-mail attachments or following Web links from unknown sources,” Greenbaum said.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。