Workaround for Multiple Microsoft Symbolic Link Files Vulnerabilities (MS08-014)
| Check Point Reference: | SBP-2008-04 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Bulletin MS08-014 | |
| Industry Reference(s): | CVE-2008-0112 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Microsoft Office 2000 SP3 Microsoft Office XP SP3 Microsoft Office 2003 SP2 2007 Microsoft Office System Microsoft Office Excel Viewer 2003 Microsoft Office 2004 for Mac Microsoft Office 2008 for Mac Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats | ||
| Vulnerability Description A remote code execution vulnerability was reported in the way Microsoft Excel imports Symbolic Link (SYLK) files into Excel. Symbolic Link (SYLK) is a Microsoft file format typically used for exchanging data between applications, particularly spreadsheets. SYLK files conventionally have a .slk suffix. Successful exploitation of this vulnerability may allow a remote attacker to take complete control of an affected system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS08-014 |
|
|
Vulnerability Details The vulnerability is due to an error in Microsoft Excel that fails to sufficiently validate file data when importing a file into Excel. An attacker can exploit this flaw via a specially crafted SYLK file. Successful exploitation of this issue may allow a remote attacker to execute arbitrary code on a target system. |
Protection Overview
By enabling this protection, SmartDefense will detect and block the transferring of SYLK files over HTTP.
Since the protection offered in this advisory may degrade performance and block access to legitimate files, users are advised to use this protection as a workaround till all systems are patched.
In order for the protection to be activated, update your VPN-1 product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.