Linked by Thom Holwerda on Tue 14th Mar 2006 23:51 UTC
Microsoft As part of its monthly patch cycle, Microsoft on Tuesday released fixes for six security holes in Office and one flaw in Windows. Five of the six vulnerabilities in Office are specific to Excel. The most serious flaws could allow an attacker to gain control over a vulnerable PC running the spreadsheet program, Microsoft said in Security Bulletin MS06-012. In all cases, the miscreant would have to persuade the user to open a malformed Excel file, the software maker said. The sixth problem affects a range of Office applications, including some versions of Word, Outlook & PowerPoint. Microsoft's second update deals with an operating system issue that affects Windows XP with Service Pack 1 and Windows Server 2003.
Order by: Score:
Running a malformed Excel file?
by ma_d on Wed 15th Mar 2006 01:54 UTC
ma_d
Member since:
2005-06-29

Ahem, if you can get them to open up random Excel files I bet you can get them to run random batch files too...

Anyway, good they fix it, but seriously, this is newsworthy?

Reply Score: 1

hmm
by Beryllium on Wed 15th Mar 2006 05:57 UTC
Beryllium
Member since:
2005-07-08

any comment on whether OpenOffice's excel import filter is vulnerable?

Reply Score: 1

RE: hmm
by Celerate on Wed 15th Mar 2006 08:04 UTC in reply to "hmm"
Celerate Member since:
2005-06-29

Why would it be? Microsoft and OpenOffice.org don't share code.

Reply Score: 1

This is insane
by r2d2d3d4d5 on Wed 15th Mar 2006 13:38 UTC
r2d2d3d4d5
Member since:
2005-12-31

Why should a little Excel file be so dangerous? MS really need to limit what user run programs/files should be allowed to do.

Re: Running a malformed Excel file?
By ma_d (1.16) on 2006-03-15 01:54:28 UTC
Ahem, if you can get them to open up random Excel files I bet you can get them to run random batch files too...

Anyway, good they fix it, but seriously, this is newsworthy?


Personally I'd have felt much more secure opening a random Excel/Word file than running random batch/exe files. My mistake obviously, but I suspect a lot of people that aren't aware how potentially dangerous files are (as apposed to programs) will be in the same boat.

Reply Score: 2