SLAC Computer Security Awareness and Training
Search SLAC
Microsoft Office Web Components Vulnerability Microsoft Office Web Components Vulnerability

Microsoft Office Web Components Vulnerability

 

 For the non-centrally managed Windows computers

 

If you have a Windows computer that is not centrally managed you should read the Microsoft Advisory (972472)

 

Summary:

If you publish or view Microsoft spreadsheets, charts or databases on the web, there is currently a reported vulnerability that when Internet Explorer uses the Active X control, the control may corrupt the system state.

Which means if you use IE to visit a site that has been hacked, to view or upload a spreadsheet, chart or database, there is  a possibility that you could get something (malware) that you didn't ask for.   Your antivirus software probably doesn't a signature for this exploit yet.

Read the article and apply the workaround.

A workaround is available at http://support.microsoft.com/kb/973472.

 

According to Microsoft, the following operating system versions are affected:

Microsoft Office XP Service Pack 3

Microsoft Office 2003 Service Pack 3

Owner: SLAC Computer Security
Page Created: 07/14/2009
Last Updated: 07/14/2009
Feedback: Please send to
Computer Security Feedback