Feeds

MS Office virus could infect without you opening attachment

If your browser automatically executes a CALL function, then all sorts of horrid things may be possible

  • alert
  • submit to reddit

Internet Security Threat Report 2014

Israeli security outfit Finjan Software has warned of how a potentially serious Excel-related virus could spread and inflict damage without the recipient opening an email attachment. Finjan says that "All 3.x and 4.x versions of the Microsoft Internet Explorer Browsers and Netscape Navigator browsers 3.x and 4.x (except Navigator 4.5) are vulnerable, as well as all HTML-aware email applications such as Outlook 98." The virus in question is Russian New Year, which uses the Excel CALL function in Office 95 and Office 97. This allows external executables to be started from within a spreadsheet cell, without the user knowing it's happening. Finjan explains how this would work via a browser: "On a Web page, Web developers include services to various file content types from a server to a browser. Suppose the files end with .XLS extensions. Then it is likely that these files will be associated with the Excel program. In this case, the .XLS files transferred to a browser will be passed immediately and processed by the referenced application - in this case, Excel. When Excel is opened, it executes functions in the cells of the spreadsheet. If one of the functions has a maliciously coded CALL function then it is possible that the Excel spreadsheet can be used to copy an executable program to the hard disk and execute it." But that doesn't mean you have to physically open the link yourself. Vulnerable browsers and email programs can execute the CALL function automatically without the email actually being opened, therefore it seems conceivable that the infection could spread without users even noticing it was happening. Freelance writer Deborah Radcliff reported on this a few days ago in Computerworld, and she comes up with some possible consequences. A mass mail could be used to distribute the virus, which could be used for espionage purposes (suck data from your corporate rivals) or for sheer destruction, creating and writing data to the recipients' hard disks. She also suggests the possibility that the Melissa approach, where the virus apparently comes from a colleague or friend, could be used in conjunction with Russian New Year. According to Finjan, the solutions are convoluted, and not particularly attractive for people who use the CALL function frequently. You need to run Office 97 (there's no fix for 95) with service packs 1 and 2 installed and the Microsoft patch to disable the CALL function. If you're using IE 3.x, upgrade to 4.x and set the security level to highest. Navigator users should switch to 4.5. Our thanks to Windows 98 Central, a useful site for monitoring all things Windows-related, for drawing this one to our attention. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Bladerunner sequel might actually be good. Harrison Ford is in it
Go ahead, you're all clear, kid... Sorry, wrong film
Euro Parliament VOTES to BREAK UP GOOGLE. Er, OK then
It CANNA do it, captain.They DON'T have the POWER!
Musicians sue UK.gov over 'zero pay' copyright fix
Everyone else in Europe compensates us - why can't you?
I'll be back (and forward): Hollywood's time travel tribulations
Quick, call the Time Cops to sort out this paradox!
Megaupload overlord Kim Dotcom: The US HAS RADICALISED ME!
Now my lawyers have bailed 'cos I'm 'OFFICIALLY' BROKE
Forget Hillary, HP's ex CARLY FIORINA 'wants to be next US Prez'
Former CEO has political ambitions again, according to Washington DC sources
prev story

Whitepapers

Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.