Encyclopedia

MS09-021

 
Threat LevelLow threatDamageHighDistributionNot widespread
Nombre común:MS09-021
Nombre técnico:MS09-021
Peligrosidad:Media
Alias:Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution, Vulnerabilidades en Microsoft Office Excel podrían permitir la ejecución remota de código
Tipo:Vulnerabilidad
Efectos:  

It is a group of critical vulnerabilities in certain versions of Excel and Office, which allows hackers to gain remote control of the affected computer with the same privileges as the logged-on user.

Plataformas que infecta:

Otros

Fecha de detección:10/06/2009
Detección actualizada:11/06/2009
EstadísticasNo

Descripción Breve 

    

MS09-021 is not categorized as virus, worm, Trojan or backdoor. It is a group of critical vulnerabilities in certain versions of Excel and Office, which allows arbitrary code to be remotely executed in the vulnerable computer.

The affected versions are:

  • Excel 2000 on Office 2000, Excel 2002 on Office XP, Excel 2003 on Office 2003, Excel 2007 on Office 2007.
  • Office Viewer 2003 and Office Excel Viewer.
  • Office SharePoint Server 2007.
  • Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats.
  • Office 2004 and Office 2008 for Mac.
  • Open XML File Format Converter for Mac.

 

If exploited successfully, MS09-021 allows hackers to gain remote control of the affected computer with the same privileges as the logged-on user. If this user had administrator rights, the hacker could take complete control of the system: create, modify or delete files, install programs, create new user accounts, etc.

MS09-021 is exploited by creating a specially crafted Excel file and sending it via email or hosting it in a website and convincing users to open it.

 

If you have any of the vulnerable programs installed on your computer, it is recommended to download and apply the security patch for this vulnerability. Click here to access the web page for downloading the patch.

Bear in mind that MS09-021 replaces a previous bulletin, called MS09-009.

Información actualizada:  11/06/2009 

Virus News

3/10/09.-More than 10 Million Worldwide Were Actively Exposed to Identity Theft in 2008

3/5/09.-Cyber-crooks manipulate Internet searches to sell fake antivirus products

3/2/09.-VideoPlay adware infections grew 400% in February through malicious use of Web 2.0 pages

[+ Noticias]