Content

Exploit-MSExcel.r

Type
Trojan
SubType
Exploit
Discovery Date
09/02/2008
Length
Varies
Minimum DAT
5375 (09/02/2008)
Updated DAT
5862 (01/15/2010)
Minimum Engine
5.2.00
Description Added
09/02/2008
Description Modified
02/24/2009 2:27 PM (PT)
Risk Assessment
Corporate User
Low-Profiled
Home User
Low-Profiled

Tab Navigation

Characteristics

-- Update February 24, 2008 --

McAfee has observed variants of Exploit-MSExcel.r which attempt to exploit the vulnerability described in CVE-2009-0238. Additional information on this vulnerability can be found at:

http://www.microsoft.com/technet/security/advisory/968272.mspx
--

This is a generic detection for malicious XLS documents targeting Microsoft Excel vulnerabilities.

When successful, it may install a trojan onto the vulnerable machine such as BackDoor-DUE.

Symptoms

  • Abnormal termination of Microsoft Excel application.
  • Unexpected dropping of files from Microsoft Excel.

 

Method of Infection

This trojan exploits a vulnerability in Microsoft Excel.

 

Removal

Variants

Variants

    N/A

All Information

Overview -

-- Update February 24, 2008 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://tech.yahoo.com/news/pcworld/20090224/tc_pcworld/attackerstargetingunpatchedvulnerabilityinexcel2007
--

This is a generic detection for malicious XLS documents targeting Microsoft Excel vulnerabilities.

 

Characteristics

Characteristics -

-- Update February 24, 2008 --

McAfee has observed variants of Exploit-MSExcel.r which attempt to exploit the vulnerability described in CVE-2009-0238. Additional information on this vulnerability can be found at:

http://www.microsoft.com/technet/security/advisory/968272.mspx
--

This is a generic detection for malicious XLS documents targeting Microsoft Excel vulnerabilities.

When successful, it may install a trojan onto the vulnerable machine such as BackDoor-DUE.

Symptoms

Symptoms -

  • Abnormal termination of Microsoft Excel application.
  • Unexpected dropping of files from Microsoft Excel.

 

Method of Infection

Method of Infection -

This trojan exploits a vulnerability in Microsoft Excel.

 

Removal -

Removal -

Variants

Variants -

    N/A