At the time of writing fully patched and up to date versions of Microsoft Excel 2000, Excel 2003, or Excel XP are vulnerable. As well as Excel 2004 and 2004 v. X for Mac. The security flaw requires that a user load a file that has been specifically made to infect a victim. The most likely method of infection will be via e-mail attachments. Users should be weary about any unsolicited spreadsheet files they receive by email. There is also a chance that an infected spreadsheet which is opened from a website can be used as an attack vector.
Like any file that a user receives all '.xls' files that are downloaded from the Internet should be scanned with one of many popular virus scanning programs. Be particularly weary of email attachments that you are not expecting. Most virus scanners have updated their databases to detect this virus.
The damage can be potentially mitigated if the user that accidentally opened the virus infected file was using an account that was not configured to have administrator rights on the system. The virus can only gain the same access rights as the user with this attack, any limitations the user has for security reasons are inherited by the virus. This can potentially limit the ability of the virus to properly install its payload trojan program.
Several versions of Excel are not vulnerable to this particular attack. These include the version with Microsoft Office 2007, and the Microsoft Works 2004, 2005, 2006 packages.
If an infected '.xls' file is opened the excel program will close immediately and unexpectedly. It creates a file called 'Top10.exe' in the default temporary directory, which is usually 'C:\windows\temp\'. This file is run after it is created by the virus installing the trojan package.
Microsoft has confirmed that it is aware of the problem but has not yet released a fix to close the hole. The virus that was found in the wild by security research companies installed a variant of 'BackDoor-CWA' trojan. This piece of software is used to gain remote access to the infected systems. It may be capable of checking in with a remote system to notify the attacker that another system is under their control. The trojan package also establishes it self in the system so that it is run when the computer starts and stays running disguising itself as an important system service.
Microsoft 'Microsoft Security Advisory (932553)' URL: http://www.microsoft.com/technet/security/advisory/932553.mspx
McAfee 'Exploit-MSExcel.h' URL: http://vil.nai.com/vil/content/v_141393.htm
Published by Ryan Drew
Web content for hire, able to write to specified writing style and content. View profile
- Composing Effective Office MemorandumsThis article will help you to prepare a professional office memorandum.
- Tips on Office Leasing and PurchasingA look at the basics of renting office space, including space and price considerations and resources.
- 10 Items You Need When Setting Up Your First Home Office10 Items You Need When Setting Up Your First Home Office
Your Job as an Office ProfessionalOffice Support positions sport many titles such as Administrative Assistants, Office Assistants, Secretaries, "Something" Clerk and many other labels. Acquiring industry-specif...- Post Katrina, Uptown New Orleans ReturnsIt's been almost two months since Hurricane Katrina flooded 80% of New Orleans. While much of the city remains uninhabited and uninhabitable, Uptown shows signs of normality. But it's not the "old normal," it's a "ne...
- New England Journal of Medicine Study on Heart Attack Patients
- Microsoft Office Student & Teacher Edition
- From Here to Home Office: Setting Up a Productive Shop
- Organizing a Home Office
- Top Hair Salons in Ithaca, New York
- Three Steakhouses in Ithaca, New York
- Feng Shui Your Office or Workspace with This How-To Guide



