PC Antivirus Reviews 2010

2010 Antivirus Software Report

2010 PC Antivirus Firewall Software &
Internet Security Suite Reviews

VIPRE Antivirus + Antispyware
VIPRE
BitDefender Antivirus 2010
BitDefender
Kaspersky Anti-Virus 2010
Kaspersky
Panda Antivirus 2010
Panda
Norton AntiVirus 2010
Norton
McAfee VirusScan Plus 2010
McAfee
CA Anti-Virus 2010
CA
Trend Micro AntiVirus Plus 2010
Trend Micro
antivirus reviews
Get Free Antivirus Software Coupons!
Your Name
Your E-Mail
 
antivirus resources
 
antivirus help
PC Antivirus Update

Antivirus Update Home | New Trojan Targets Unpatched Microsoft Excel Flaws... » | Conficker Worm Technical Analysis » | Microsoft Patch Tuesday: Another Angle » | Conficker Worm Reward Offered by Microsoft » | Antivirus protection the old-fashioned way... » | Security patches in Firefox 3.0.6, upgrade urged » | Virus Protection Warning about Autorun.exe (more o... » | Downandup, Downadup, Kido!, Conficker: Update » | Worm Attack: 9 Million PCs Hit » | Windows PCs Vulnerable to Worm Attack »  

Thursday, March 5, 2009  

Microsoft Not Patching Excel Security Flaw

In one of the more disappointing announcements of late coming from Microsoft, they announced today that even though they were rolling out three security updates, including a critical one, they weren't fixing one in Excel that, sadly, crackers are now exploiting.

Symantec's researchers, according to a Computerworld article on the Excel bug, described it this way:
"The vulnerability is a file format bug in all supported versions, including the latest -- Excel 2007 on Windows and Excel 2008 for the Mac."
Given that it is such a widespread bug, it makes sense that it takes time to sort through all the ramifications of such a fix; however, we'd really hoped that for that very reason, it being a widespread bug, because it does affect all versions of Excel, Microsoft would have taken after this patch aggressively and come up with a fix more quickly.

Now, given that Microsoft only releases patches 12 times a year, it's especially important to know that the person sending you an Excel spreadsheet really has sent the sheet, and it's equally important to make sure you're staying atop antivirus software updates.

We're going to continue to monitor the status of this bug and any fallout from it (or a subsequent patch) here, so watch this section for details as they become available.

Editors update: Having missed the link to the Microsoft Security Advisory on Excel, I thought it prudent to include it should someone come across this post looking for information on dealing with the exploit.

Since having posting this piece Microsoft has subsequently made several patches available for the different versions of Microsoft Office. Here's MS security bulletin MS09-009 on how to patch Microsoft Excel against this (and other vulnerabilities).

Links to this post

Create a Link

2010 PRODUCTS REVIEWED


Get informed...
Stay informed...

Want to get the latest news from our blog delivered straight to your inbox? (It's free.)

Enter your email address:




Copyright © 2010 pcAntivirusReviews.com