Encyclopedia

Panda Internet Security 2010

Panda Internet Security 2010

Full protectión for complete peace of mind on the Internet.

* Includes 3 months' services FREE

MS09-067

 
Threat LevelLow threatDamageHighDistributionNot widespread
Common name:MS09-067
Technical name:MS09-067
Threat level:Medium
Alias:Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution, Vulnerabilidades en Microsoft Office Excel podrían permitir la ejecución remota de código
Type:Vulnerability
Effects:  

It is a group of important vulnerabilities in certain versions of Excel and Office, which allows hackers to gain remote control of the affected computer with the same privileges as the logged-on user.

Affected platforms:

Other

First detected on:Nov. 11, 2009
Detection updated on:Nov. 11, 2009
StatisticsNo

Brief Description 

    

MS09-067 is not categorized as virus, worm, Trojan or backdoor. It is a group of important vulnerabilities in certain versions of Excel and Office, which allows arbitrary code to be remotely executed in the vulnerable computer.

The affected versions are:

  • Excel 2002 on Office XP, Excel 2003 on Office 2003, Excel 2007 on Office 2007.
  • Office Excel Viewer 2003.
  • Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats.
  • Office 2004 and Office 2008 for Mac.
  • Open XML File Format Converter for Mac.

 

If exploited successfully, MS09-067 allows hackers to gain remote control of the affected computer with the same privileges as the logged-on user. If this user had administrator rights, the hacker could take complete control of the system: create, modify or delete files, install programs, create new user accounts, etc.

MS09-067 is exploited by creating a specially crafted Excel file and sending it via email or hosting it in a website and convincing users to open it.

 

If you have any of the vulnerable programs installed on your computer, it is recommended to download and apply the security patch for this vulnerability. Click here to access the web page for downloading the patch.

Bear in mind that MS09-067 replaces a previous bulletin, called MS09-021.

Last updated:  11/11/2009 

Thanks to Collective Intelligence, Panda's exclusive cloud-computing technology, the company's 2010 solutions leverage the knowledge gathered from the community of millions of Panda users around the world. Each new file received is automatically classified within six minutes and the Collective Intelligence servers classify more than 50,000 new malware samples every day. These technologies correlate information on malware received from each computer to continuously improve the protection level for the worldwide community of users. Panda's 2010 solutions have continuous, real-time contact with this vast knowledge base allowing the company to offer users the fastest response against the new malware that appears every day.

Virus News

Help your friends against viruses: share, save and subscribe to our security content. Thank you.

Share/Bookmark

Panda Security and Defence Intelligence Coordinate Massive Botnet Shutdown with ...

New FTLog.A worm spreads through Fotolog social networking website, reports Pand...

Spybot.AKB spreads across P2P networks and email using Google, Twitter, Amazon, ...

[+ News ]