Related Stories

  • Comment: Smart grid security – the path ahead
    IOActive’s Joshua Pennell implores AMI vendors to use a secure development lifecycle to maintain the security and availability of ‘smart grid’ technologies
  • An injection of new ideas
    Securing IT means coping with Donald Rumsfeld’s ‘known unknowns’ – expected attacks whose nature is a surprise. Concepts from medicine, game theory and crowd sourcing may help, finds Danny Bradbury
  • Internet Explorer zero-day vulnerability spreads to Microsoft Office as fixes surface
    Microsoft has scheduled an out-of-band patch for the zero-day vulnerability in Internet Explorer, just as other fixes for the problem began to surface. The company has also admitted for the first time that the attack could be used to compromise a computer using Microsoft Office.
  • The User is Not the Enemy: How to Increase Information Security Usability
    People have long been accused of being the ‘weakest link’ in information security, but what if lack of usability and security training is actually at the heart of the matter? Wendy M. Grossman investigates
  • Infosecurity - the week in brief
    Black Hat DC This week, Black Hat DC was on in Arlington, VA. Moxie Marlinspike announced a new attack against SSL that forces HTTPS traffic into HTTP to allow a man in the middle attack. Dan Kaminsky, who discovered the infamous DNS flaw last year and criticized SSL at the the time, reacts here. He also resolved at the conference to take two months off work to promote the adoption of DNSSEC - a more secure DNS standard that has not been widely implemented.

News

Microsoft Admits Excel Zero-Day Flaw

26 February 2009

Microsoft has warned customers about a zero-day flaw in Excel that could allow for remote code execution if specially-crafted files are opened in the spreadsheet program.

The flaw, which the company is currently investigating following initial reports, uses a malicious Excel spreadsheet file to try and access an invalid object. This creates a buffer overflow condition that enables the attacker to potentially execute arbitrary code.

The company says that it has already seen attacks in the wild, although these have been targeted attacks rather than mass attacks designed to compromise a large population. The firm has promised a patch, but hasn't set a date. It hasn't ruled out the possibility of an out-of-band patch should conditions escalate.

In the meantime, it has released a generic signature for inclusion in its two client-side anti-malware products, Forefront Client Security, and Windows Live OneCare.

In a web-based attack, an attacker would lure a victim to a web site and get the to open the malicious spreadsheet after downloading it. It could also be distributed via email. It affects all versions of Excel since Office 2000 (including Office Mac 2008), along with the Excel viewer.

"An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights," said the company, further emphasizing the importance of running Windows in least-privilege mode.

Buffer overflows have been a thorn in the Microsoft's side in spite of the secure development lifecycle which it has been pursuing for the past seven years. The company's research team in Silicon Valley is working on a project called XFI on software assurance methods that could enable the company to better predict when a program is going to branch into an address space that it shouldn't.

"The instrumentation of the code on the fly to trap all that stuff," said Roy Levin, the Silicon Valley Lab's managing director, who explained that XFI is designed to work on binaries rather than source code.

 

This article is featured in:
Application Security Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.