Critical Excel vulnerability features in July's 'patch Tuesday'

Excel 2007 featured in the security updates issued by Microsoft on July 10, the traditional second Tuesday scheduled for the company's monthly bulletins.

The Excel vulnerability could allow malicious code to be downloaded and run by causing a "buffer overflow" when a user opens a specially crafted Excel file. People with administrative user rights on their machine will be more at risk that those without.

Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

It is rated as critical for Microsoft Office 2000 and Excel 2000 with Service Pack 3 patches applied, but important for Office XP/Excel 2002, 2003 (Service Pack 2) and Excel 2007.

For an attack to be successful a user must open an attachment that is sent in an e-mail message.

Critical alerts were also published concerning the Windows Active Directory and .NET Framework. See July's security bulletin summary for links to full descriptions and patch downloads.


Already a member? log in here.

Editor's Choice