You're in: Panda Security > Home Users > security-info > about-malware > encyclopedia > overview
Active Scan. Scan your PC free
Panda Security Product Line 2012

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Encyclopedia GetVirusCard True 0

MS09-067

 
Threat LevelLow threatDamageHighDistributionNot widespread

Effects 

MS09-067 is not categorized as virus, worm, Trojan or backdoor. It is a group of important vulnerabilities in certain versions of Excel and Office, which allows arbitrary code to be remotely executed in the vulnerable computer.

The affected versions are:

  • Excel 2002 on Office XP, Excel 2003 on Office 2003, Excel 2007 on Office 2007.
  • Office Excel Viewer 2003.
  • Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats.
  • Office 2004 and Office 2008 for Mac.
  • Open XML File Format Converter for Mac.

 

The addressed vulnerabilities are:

  • Excel Cache Memory Corruption vulnerability.
  • Excel SxView Memory Corruption vulnerability.
  • Excel Featheader Record Memory Corruption vulnerability.
  • Excel Document Parsing Memory Corruption vulnerability.
  • Excel Index Parsing vulnerability.
  • Excel Document Parsing Memory Corruption vulnerability.
  • Excel Field Sanitization vulnerability.

All these vulnerabilities are due to the way Excel parses a specially crafted Excel spreadsheet file.

 

If exploited successfully, MS09-067 allows hackers to gain remote control of the affected computer with the same privileges as the logged-on user. If this user had administrator rights, the hacker could take complete control of the system: create, modify or delete files, install programs, create new user accounts, etc.

MS09-067 is exploited by creating a specially crafted Excel file and sending it via email or hosting it in a website and convincing users to open it.

 

If you have any of the vulnerable programs installed on your computer, it is recommended to download and apply the security patch for this vulnerability. Click here to access the web page for downloading the patch.

Bear in mind that MS09-067 replaces a previous bulletin, called MS09-021.