Content

Exploit-MSExcel.p

Type
Trojan
SubType
Exploit
Discovery Date
01/10/2008
Length
Varies
Minimum DAT
5204 (01/10/2008)
Updated DAT
5615 (05/14/2009)
Minimum Engine
5.1.00
Description Added
01/10/2008
Description Modified
03/12/2008 4:14 AM (PT)
Risk Assessment
Corporate User
Low-Profiled
Home User
Low-Profiled

Tab Navigation

Characteristics

-- Update March 12, 2008 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.crn.com/security/206903067

This detection covers malware that exploits an unpatched vulnerability in Microsoft Excel. CVE-2008-0081

More details of this vulnerability from the vendor at:

http://www.microsoft.com/technet/security/advisory/947563.mspx

Symptoms

When successful, the exploit may install additional malware onto the victim's machine.

Method of Infection

Removal

AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

-- Update March 12, 2008 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.crn.com/security/206903067

This detection covers malware that exploits an unpatched vulnerability in Microsoft Excel. CVE-2008-0081.

 

Aliases

  • Exploit:Win32/Exrec.gen!A (Microsoft)
  • TR/Drop.MSExcel.Agent.L (Avira)
  • Trojan-Dropper.MSExcel.Agent.l (Kaspersky)
  • Trojan.Mdropper (Symantec)
  • W97M/Exploit-OleData (Ahnlab)
  • X97M/TrojanDropper.Agent.L (ESET)

Characteristics

Characteristics -

-- Update March 12, 2008 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.crn.com/security/206903067

This detection covers malware that exploits an unpatched vulnerability in Microsoft Excel. CVE-2008-0081

More details of this vulnerability from the vendor at:

http://www.microsoft.com/technet/security/advisory/947563.mspx

Symptoms

Symptoms -

When successful, the exploit may install additional malware onto the victim's machine.

Method of Infection

Method of Infection -

Removal -

Removal -

AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A