Vulnerability: (968272) Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution
Back to Latest vulnerabilities homepage
Click any highlighted term for further explanation.
| Details | |
|---|---|
| Vulnerability name/brief description | Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (968272) |
| CVE/CAN name |
CVE-2009-0238 |
| Vendor threat level | Critical |
| SophosLabs threat level | High |
| Solution |
At the time of writing this analysis a security update was not available from the vendor. |
| Vendor description |
Microsoft is investigating new public reports of a vulnerability in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability. |
| SophosLabs comments |
The vulnerability may result in remote code execution. It can be exploited by enticing the user to open specially crafted Excel files. The vulnerability has been assigned a high threat level. |
| SophosLabs testing result | N/A |
| Currently known exploits |
SophosLabs have received initial sample exploiting this vulnerability and detection has been published using name Troj/Mdrop-BZL. On 27th February 2009 SophosLabs have received several samples exploiting this vulnerabilty and have issued detection for them as Troj/Evenex-A and Troj/Evenex-B. |
| First sample seen | N/A |
| Discovery date | 24 February 2009 |
| Affected software |
Microsoft Office Excel 2000 Service Pack 3 |
| References |
http://www.microsoft.com/technet/security/advisory/968272.mspx |
| Credits | |
| Revisions |
27 February 2009 - analysis updated with details of detections issued for new samples 24 February 2009 - initial analysis written |
Explanation of terms
Vulnerability Name/Brief Description:
Vendor identifier plus a brief description of the type of attack.
CVE/CAN Name:
Currently assigned CVE name. If a CVE name doesn't exist the CAN name will be used until a CVE has been assigned.
Vendor Threat Level:
Threat level assigned by the vendor
SophosLabs Threat Level:
Threat level assigned by SophosLabs
- LOW RISK - There is little chance of this vulnerability being actively exploited by malware.
- MEDIUM RISK - There is a possibility of this vulnerability being actively exploited by malware.
- HIGH RISK - There is a strong possibility of this vulnerability being actively exploited by malware.
- CRITICAL RISK - This vulnerability will almost certainly be actively exploited by malware.
Solution:
Vendor-supplied Patch identifier and recommended solution, or workaround if applicable.
Vendor Description:
Summary of the cause and potential effect of the vulnerability provided by the vendor.
SophosLabs Comments:
SophosLabs' opinions and observations of the vulnerability in question.
SophosLabs Testing Result:
Details of completed lab testing, if applicable. Please note that the lab test environment may differ significantly from user environments.
Currently Known Exploits:
List of identities for known exploits, if applicable.
First Sample Seen:
Date of the first sample seen by SophosLabs.
Discovery Date:
Date of the earliest known publically disclosed advisory.
Affected Software:
Vulnerable platforms and software versions.
If you need more information or guidance, then please contact technical support.
- Article ID: 53421
- Created: 25 Feb 2009
- Last updated: 22 Mar 2010


