Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Networking

    Excel Zero-Day Still Unpatched

    Written by

    Ryan Naraine
    Published February 12, 2008
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Microsoft has issued 11 security bulletins with patches for 17 documented software flaws. But Windows IT administrators are raising alarm bells because Microsoft hasn’t issued a fix for a critical-and already exploited-Excel vulnerability.

      Microsoft originally planned to ship a dozen bulletins, but at the eleventh hour one of the “critical” advisories was yanked to address concerns about patch quality.

      Microsoft officials would not say which product was affected by the missing bulletin, but it’s a general assumption in security circles that it was related to a memory corruption issue in Microsoft Excel 2004 and earlier versions.
      On Jan. 15, 2008, Microsoft acknowledged the bug in a pre-patch advisory and warned that unknown attackers were using rigged .xls files to launch targeted code-execution attacks.
      A spokesperson for the MSRC (Microsoft Security Response Center) confirmed for eWEEK that the Excel zero-day is still unpatched.
      According to Jonathan Bitle, director of technical account management at Qualys, the missing Excel update is a “big worry.”
      “Excel is such a [widely used] product by business users all over the world that it’s a big concern to leave a known vulnerability unpatched for an extended period of time. I imagine there will be an uproar from Microsoft customers,” Bitle said in an interview.
      “I’m really surprised they didn’t get this [Excel] fix out the door, since it’s known that it’s been exploited in the wild,” he added.
      However, Bitle said Windows administrators almost universally prefer a fully tested, high-quality update instead of a patch that causes applications to break or doesn’t fix the underlying vulnerability.
      “Anytime there’s a potential for a company to have a false sense of security, I think that’s worse than leaving it unpatched. The first person to figure out that the patch doesn’t work will probably be someone with malicious intent. It’s good to err on the side of caution when it comes to patch quality,” Bitle said.

      Click here to read more about zero-day attacks against Microsoft Excel.

      In all, the February Patch Tuesday batch includes six “critical” and five “important” bulletins and provides cover for serious code execution holes in Internet Explorer, Microsoft Word, Microsoft Office, OLE automation, Microsoft Publisher and the WebDAV (Web-based Distributed Authoring and Versioning) Mini-Redirector. The cumulative IE update fixes a total of four vulnerabilities and is rated critical (remote code execution) for all supported versions of the browser, including the newest Internet Explorer 7 on Windows Vista.

      Most of the “critical” updates address flaws in widely deployed products. For example, the Microsoft Word and Microsoft Publisher applications, which fall under the Office umbrella, both get a major security refresh to cover multiple vulnerabilities.

      “While the batch of critical vulnerabilities all require some sort of user interaction to exploit, the interaction can be as simple as visiting a trusted Web site that has first been exploited by an attacker,” said Ben Greenbaum, senior research manager for Symantec Security Response.
      Greenbaum said the client-side bugs can be exploited to distribute malware through trusted sites, e-mail attachments or links embedded in instant messaging conversations.
      “These vulnerabilities underscore the importance of having a full security suite to protect consumers and enterprises from being exploited, since they can no longer only rely on traditional best practices alone, such as avoiding unknown or unexpected e-mail attachments or following Web links from unknown sources,” Greenbaum said.

      Ryan Naraine
      Ryan Naraine

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.