View Single Post
  #8   Report Post  
Posted to microsoft.public.excel, microsoft.public.excel.misc,microsoft.public.excel.worksheet.functions
Harlan Grove[_2_] Harlan Grove[_2_] is offline
external usenet poster
 
Posts: 1,231
Default FYI - Microsoft Acknowledges XL Flaw

"T. Valko" wrote...
But I'm just wondering if any Excel expert
can add to what the blog says.


I'm FAR from an expert but here's what I noticed that the article
*didn't* say:

It's not a malicious macro coded threat. In other words, disabling
macros won't stop it.

....

The MSFT security advisory also didn't mention the precise file
formats that could carry such payload that the affected versions of
Excel (and the Excel 2003 VIEWER, fer cryin'g out loud!) mishandle.
Recall the penitent words of a few senoir MSFT people just after the
SP3 blockade was publicised: it's not the file formats themselves that
are dangerous, it's the software that loads those files that would
cause problems.

If MSFT hasn't been able to figure out how to make Excel load binary
spreadsheet files safely through Excel 2003, what are the odds they
finally figured out how to do so with the .XLSB file format in Excel
2007? Conversely, will Excel 2007 SP-1 block .XLSB files? Just
wondering.