Patch to close an Excel security hole
Summary
In 1999 Microsoft released a patch of almost 3 MB for an Excel hole through which attackers could delete files on the hard disk. The cause was a bug in the database driver, triggered by spreadsheets from emails or websites, against which macro virus protection was useless. Excel 97 and 2000 were affected, although Microsoft’s German pages declared Office 2000 safe.
Ideas
- A document could access the file system through the database driver.
- Macro virus protection does not help if the attack does not use macros.
- Spreadsheets from emails and websites became the attack path.
- The vendor’s information differed depending on the language version of the website.
Insights
- Protection mechanisms often only cover the known attack path, not the entire functionality of a format.
- Contradictory vendor information delays patching affected systems.
Facts
- The patch was almost 3 MB in size.
- Microsoft confirmed that Excel 97 and Excel 2000 were affected.
References
Critique
- The report names neither the identifier nor the scope of the database driver bug, which makes checking your own systems harder.
Recommendations
- Open Office documents from unknown sources only in protected view or in a sandbox.
- With security advisories, compare the information in several of the vendor’s language versions.
Links to the original source and the Web Archive open in a new tab.