|
ALARM Group ALERT - click for a description of ALARM, The Computing Alert System Alert Number: 062706-01 Alert Date: 6/27/06 Alert Title: Excel Files Can Carry Security Exploits Update-to: none OS/Platform/Application: Microsoft Excel 2003 Microsoft Excel XP (2002) Microsoft Excel for Mac Category: ALERT Severity: MEDIUM Attention: All Employees, Desktop support personnel |
Summary: Several Vulnerabilities in MS Excel Can Result in Compromised Systems. Microsoft has confirmed that their Excel spreadsheet program contains a number of vulnerabilities than when exploited can result in remote, unauthorized access to your computer. There is currently no patch available from MS to correct these flaws. Therefore, it is important that employees take certain precautions when receiving Excel files as email attachments.
Recommended Actions: Please exercise caution when opening Excel (spreadsheet) files received as email attachments. Do not open the file without confirming that it was sent by your correspondent. In general, when receiving MS Office files as attachments, save the attached file first, then open it with the Office application, e.g., Word, Excel. Do not open it directly from the email link.
ITS Actions: ITS is monitoring the situation for continued developments.
Resources:
US-CERT
http://www.us-cert.gov/cas/techalerts/TA06-167A.html
MS Security Advisory (921365)
http://www.microsoft.com/technet/security/advisory/921365.mspx