1. /
  2. Security Response/
  3. Microsoft Excel 97 / 2000 Register.ID Vulnerability

Microsoft Excel 97 / 2000 Register.ID Vulnerability

Risk

High

Date Discovered

July 11, 2000

Description

Due to the REGISTER.ID function in Microsoft Excel 97 / 2000, remote execution of native code in a DLL file is possible under certain conditions. The REGISTER.ID function must refer to a specially formed DLL file containing the arbitrary code to be executed and it must reside on the local hard drive or on a UNC share. If a user opens a .xls file containing this function, the code specified will be run at the privilege level of the user. Excel and other MS Office files can be sent and automatically opened via browsers and HTML-aware email clients. In most cases, no prompt will be given to the user before Excel is started, and no warning will be given before the code is executed.

Technologies Affected

  • Microsoft Excel 2000
  • Microsoft Excel 97
Microsoft has released the following patches which eliminates the vulnerability:

Credits

Posted to Bugtraq on July 11, 2000 by Georgi Guninski .
Copyright © Symantec Corporation.
Permission to redistribute this alert electronically is granted as long as it is not edited in any way unless authorized by Symantec Security Response. Reprinting the whole or part of this alert in any medium other than electronically requires permission from secure@symantec.com.

Disclaimer
The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.
Symantec, Symantec products, Symantec Security Response, and secure@symantec.com are registered trademarks of Symantec Corp. and/or affiliated companies in the United States and other countries. All other registered and unregistered trademarks represented in this document are the sole property of their respective companies/owners.

Threat Intelligence

Subscribe
Follow the Threat Intelligence Twitter feed
STAR Antimalware Protection Technologies
Internet Security Threat Report
Symantec DeepSight Screensaver