MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

Second Excel vulnerability emerges today

  A new vulnerability has surfaced with a proof-of-concept exploit.  So far, there are no documented reports of this being exploited in-the-wild. Users should remain cautious with an untrusted email attachment, just in case this is spammed by email later.  Microsoft is working on patches for Excel as noted in their blog entries.

Microsoft Information
http://blogs.technet.com/msrc/archive/2006/06/20/437826.aspx

Microsoft Office Long Link Buffer Overflow Vulnerability
http://secunia.com/advisories/20748/
http://www.frsirt.com/english/advisories/2006/2431

QUOTE: The vulnerability is caused due to a boundary error in hlink.dll within the handling of Hyperlinks in e.g. Excel documents. This can be exploited to cause a stack-based buffer overflow by tricking a user into clicking a specially crafted Hyperlink in a malicious Excel document.  The vulnerability has been confirmed in Microsoft Excel 2003 SP2 (fully updated). Other versions and Office products may also be affected.

Only published comments... Jun 21 2006, 01:22 AM by harry

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems