Excel XP xml stylesheet problemsFrom: Georgi Guninski (guninski@GUNINSKI.COM)
- Previous message: Russ: "Alert: Microsoft Security Bulletin - MS02-024"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 24 May 2002 20:57:41 +0300 From: Georgi Guninski <guninski@GUNINSKI.COM> To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Georgi Guninski security advisory #55, 2002
Excel XP xml stylesheet problems
Systems affected: Excel XP
Risk: Low (user interaction required)
Date: 24 May 2002
This Advisory is Copyright (c) 2002 Georgi Guninski.
You may distribute it unmodified.
You may not modify it and distribute it or distribute parts
of it without the author's written permission.
The information in this advisory is believed to be true though
it may be false.
The opinions expressed in this advisory and program are my own and
not of any company. The usual standard disclaimer applies,
especially the fact that Georgi Guninski is not liable for any damages
caused by direct or indirect use of the information or functionality
provided by this advisory or program. Georgi Guninski bears no
responsibility for content or misuse of this advisory or program or
any derivatives thereof.
Anything in this document may change without notice.
"...He (MS) later acknowledged that some Microsoft code was so flawed
it could not be safely disclosed..."
They call this trusthworthy??????
Excel XP tries to play with new technologies like XML and XSLT.
Unfortunately the Excel seem "so flawed" that if the user
opens a .xls file and chooses to view it with xml stylesheet arbitrary code
may be executed. As script kiddies know this may lead to taking full control
over user's computer. Excel does not give any warning to the user - just asks
whether to use the style sheet or not. The default option is *not* to
display with the stylesheet though.
Consider this xls file
<?xml-stylesheet type="text/xsl" href="#?m$ux" ?>
x.Run("%systemroot%\\SYSTEM32\\CMD.EXE /C DIR C:\\ /a /p /s");
written by georgi guninski
It contains both XML and a stylesheet in one file.
Do not choose to use xml stylesheets in Excel if asked.
poweroff(8) the poor windoze box if you see Excel mentions stylesheets.
Vendor status: microsoft was notified on 23 May 2002