Home > Microsoft Reissues Security Patch for Excel 2003

News

Microsoft Reissues Security Patch for Excel 2003

3/26/2008

A calculation-error bug in Microsoft Office Excel 2003, which was acknowledged by Microsoft last Friday, has been resolved with a security update.

Microsoft Security Response Center (MSRC) blogger Tim Rains pointed to an updated security bulletin, MS080-014, dated March 19. The bulletin had originally been issued on March 11 during the Patch Tuesday update cycle, with the aim of addressing four "critical" fixes in Microsoft products, including a remote code execution flaw in Excel 2003.

The initial patch fixed Excel 2003's security problem, but unmasked the calculation problem too.

The revised bulletin MS080-014 points readers to an updated security update 943985 (buried in MS080-014's FAQ), which resolves the Excel 2003 calculation error. The 943985 security update states the following under "Resolution":

"Microsoft has completed research about this issue and has re-released security update 943985 for users of Microsoft Office Excel 2003 Service Pack 2 and of Microsoft Office Excel 2003 Service Pack 3."

This rereleased Excel 2003 security fix also will be offered to users through Microsoft's Automatic Updates.

Blogger Rains explained that the Excel calculation error was associated with the use of real-time data in Excel, based on a "user-created Visual Basic for Applications solution." Such a setup returned an incorrect zero result after the initial Excel 2003 security patch had been applied.

The problem tended to affect "on-the-go finance types," according to expert opinion, and affected users tended to have "a custom-built VBA function" in place, Rains said.


Kurt Mackie is Web editor of RCPmag.com and ADTmag.com. He can be reached at kmackie@1105media.com.

Cite this Site

Kurt Mackie, "Microsoft Reissues Security Patch for Excel 2003," Campus Technology, 3/26/2008, http://www.campustechnology.com/article.aspx?aid=60139

copy text (above) for proper citation



Recommended Reading
  • IBM Unveils New Software Designed To Streamline eDiscovery

    IBM has announced the release of new Enterprise Content Management (ECM) software specifically designed to meet the needs of clients dealing with complex legal discovery requirements. The eDiscovery solutions expand on IBM's ECM platform and are intended to give organizations greater control of digitally stored documents in an effort to reduce costs and streamline the discovery process involved in litigation.

  • Microsoft Releases SQL Server 2008 to Manufacturing

    Microsoft has released SQL Server 2008 to manufacturing (RTM) and, as an evaluation edition, to subscribers of its Microsoft Development Network and TechNet services, the company announced Wednesday.

  • Security Woes Up, as PHP and OSS Make the List

    Software vulnerabilities are up this year, especially Web browser-based ones, according to a new report from IBM Internet Security Systems. The X-Force 2008 Mid-Year Trend Statistics Report, released in late July, defined the problem broadly. A vulnerability is anything that results "in a weakening or breakdown of the confidentiality, integrity, or accessibility of the computing system."

  • Textbook Publishing in a Flat World

    According to the National Association of College Stores in a 2007 survey, the average cost of a new college textbook was $53. The founders of Flat World Knowledge, which launches with its first run of college textbooks this fall, consider that too high--so high, in fact, that they'll be offering textbooks for free, at least in versions that can be read online.

  • CourseCast 2.0 Adds Podcasting, Streaming Media Features to Free Lecture Capture System

    Panopto has released CourseCast 2.0, an update to the company's classroom capture system that's available free to academic users. CourseCast 2.0 had previously been available as part of Panopto's beta program for educators since June.

  • It IS about Technology: Integrating Higher Ed into Knowledge Culture

    For more than twenty years, we educational technologists have talked about "integrating information technology into higher education." The implication was that education would stay the same and information technology would benignly slip in and cause no ruckus at all. This rhetoric no longer applies, if it ever did, and does a disservice to us as we work through the intricacies of this age.