Industry


Ads by TechWords

See your link here


Michael R. Farnum's picture
Michael R. Farnum

Hitting the Security Nerve

New Excel 0-day being exploited

Symantec is reporting that there is an exploit in the wild for an Excel 2007 and Excel 2007 SP1 zero-day remote code execution vulnerability (other versions may be affected as well).  There's not a lot of publicly available information about the trojan or the vulnerability.  Symantec is saying that the vulnerability is being exploited by a variant of the Mdropper trojan, which they are calling Trojan.Mdropper.AC.  There are no patches for this yet (which is part of the definition for 0-day, so duh).

SecurityFocus says the following about how you can be affected:

Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will result in a denial-of-service condition.

Basically this means just to be careful about Excel files you open.  If you don't trust the source, don't open it.

 

Reply
The content of this field is kept private and will not be shown publicly.
* We require you to preview your comment before posting to prevent comment spam. Please read our comments policy before posting.