By Katherine Noyes TechNewsWorld
01/16/08 1:58 PM PT
"While the attack appears to be targeted, and not widespread, we are monitoring the issue and are working with our MSRA partners to help protect customers," wrote Microsoft's Security Response Center on the group's blog. "We will update the advisory and this blog as new information becomes available."
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
Hackers are targeting users of some older versions of Microsoft (Nasdaq: MSFT) Excel with a zero-day exploit that could compromise their data, according to a security advisory Microsoft issued Tuesday.
The vulnerability is in Microsoft Office Excel 2003 Service Pack 2, along with Microsoft Office Excel Viewer 2003, Microsoft Office Excel 2002, Microsoft Office Excel 2000 and Microsoft Excel 2004 for Mac, Microsoft said. If successfully exploited on a vulnerable computer, it could enable remote code execution, the company added.
Microsoft is now investigating public reports and the extent of the vulnerability's impact on customers. Once that's done, it may provide a security update through its monthly release process or as an out-of-cycle release, it said.
"While the attack appears to be targeted, and not widespread, we are monitoring the issue and are working with our MSRA (Microsoft Security Response Alliance) partners to help protect customers," wrote Microsoft's Security Response Center on the group's blog. "We will update the advisory and this blog as new information becomes available."
Specially Crafted Files
So far, it appears users of Microsoft Office Excel 2007, Microsoft Excel 2008 for Mac and Microsoft Office Excel 2003 Service Pack 3 are not impacted, Microsoft noted, nor are those using Microsoft Office Excel 2003 Service Pack 2 with the Microsoft Office Isolated Conversion Environment deployed.
The vulnerability also cannot be exploited automatically through e-mail , it said. Rather, a user would have to open an e-mail attachment. Using the Web, an attacker would have to host a Web site that contains a specially crafted Excel file used to exploit the vulnerability, and then persuade users to visit that site via a link or instant message.
Successful exploits would give the attacker the same user rights as the local user has. For that reason, users with administrative rights could be more affected than those with more limited privileges, Microsoft said.
Users of the Office Document Open Confirmation Tool for Office 2000 will be prompted to Open, Save, or Cancel before opening a document that is attempting to exploit the vulnerability, the company noted.
Customers who believe that they have been attacked can get support here and should contact the national law enforcement agency in their country, Microsoft said.
Less-Common Target
"It's unusual to see this kind of zero-day exploit done through Excel," David Marcus, security research and communications manager for McAfee Avert Labs, told TechNewsWorld.
Indeed, within the Microsoft Office world, a full 54 percent of zero-day exploits target Word, Marcus noted. Only 23 percent target Excel, while 15 percent focus on PowerPoint and the remainder target Office in general, he said.
The last such exploit to target Microsoft Excel was more than 18 months ago, he added.
There doesn't, however, appear to have been widespread exploitation of this vulnerability so far, Marcus noted. "Zero-day exploits are typically done in very targeted fashion," he said. "Often there's a specific person or business targeted."
Meanwhile, Microsoft will be "quick to take action," he said, "and then it will be over and done with -- until the next one happens."
'Tried and True Methods'
Microsoft Office 2003 is still one of the most prevalently deployed versions of Office, Tom Bowers, senior security evangelist for Kaspersky Lab, told TechNewsWorld.
Nevertheless, "I don't think this will be very widespread because it's a very specific vulnerability," he said. "There will be a very narrow scope of people affected."
Back in the 90s, viruses were often aimed at getting notoriety for their creators, Bowers noted. Today, on the other hand, "this is about taking control of end users' computers for botnets," he explained.
"We're not seeing a lot of really new, innovative malware out there," Bowers concluded. "Basically the people doing this are using tried and true methods."
Craftier Trojan Invades 10,000 Web Sites, Stumps Security Pros January 15, 2008
The "random js toolkit" is a Javascript code that is created dynamically and provides a random filename that can only be accessed once. As a consequence, it changes every time it is accessed. The dynamic embedding, known as "code obfuscation," is done in such a selective manner that once a user has received a page with the embedded malicious code, it will not be referenced again during future visits.
Related Stories
Microsoft Has a Broken Home December 31, 2007
Microsoft has warned users of its new Windows Home Server that the device could corrupt data when saving files from certain applications. The results could ruin family photos, small-business records or anything else users save on the system. The problem is the latest of three significant quality-control fumbles Microsoft has committed this year, said analyst Michael Cherry.
Is Microsoft Hijacking SOA? November 15, 2007
The analysts also evaluate SOA's role in Green IT. Does SOA beget better energy and resources use, or does better energy conservation in IT inevitably grease the skids toward greater SOA adoption -- or both? Learn more about how return on investment and Green IT align with SOA patterns and adoption.
Microsoft Ends Resistance to EU Antitrust Ruling October 22, 2007
Microsoft has agreed to comply with all aspects of a 2004 EU ruling's penalties. "At the time the Court of First Instance issued its judgment in September, Microsoft committed to taking any further steps necessary to achieve full compliance with the commission's decision. We have undertaken a constructive discussion with the commission and have now agreed on those additional steps," the company said.
Related News Alerts
More by Katherine Noyes
FOSS and the Google Question November 19, 2009
How FOSSy is Google, really? "I find it kinda funny that folks tout that Google uses Linux when the most useful tool they have developed -- the Google FS -- they keep internally and therefore don't have to share the code!" observed Slashdot blogger hairyfeet. "So how exactly is Google different from MSFT and Apple, who have both in the past locked up free code for themselves?"
Can T-Mobile Get Its Groove Back? November 18, 2009
T-Mobile may have a hard time pulling itself out of a swamp of customer discontent if it doesn't reverse course soon. The wireless carrier has been having some bad luck that has only been compounded by some poor decisions. "It takes a long time and much effort to build customer confidence, but a very short time to lose it," remarked telecom analyst Jeff Kagan.
Microsoft Goof - One Small Snag in a Code-Licensing Quagmire November 17, 2009
Microsoft will open source the code to a Windows 7 tool in order to rectify the erroneous inclusion of code licensed under the GPL. Redmond's response to the problem "does indicate a growing maturity with respect to free and open source licenses," said RedMonk analyst Stephen O'Grady.