Version: 2008
  • On The Insider: Britney's Bikini-Clad Top 10

December 9, 2005 9:40 AM PST

eBay halts auction of Excel flaw

  • 4 comments
Related Stories

Fixes coming for Windows flaws

December 8, 2005
An online auction of a "brand new vulnerability" in Microsoft Excel had reached about $60 when eBay pulled the item late Thursday.

A seller using the name "fearwall" started the auction Wednesday evening at 1 cent. It was up to $56 on Thursday afternoon with 21 bids placed, and eBay quashed the auction soon after that.

The online auctioneer removed the item because it contravened its guidelines, eBay spokeswoman Catherine England said Friday. "The listing was pulled for violating our policy against encouraging illegal activity," she said in an e-mailed statement.

Microsoft is aware of the reported flaw and has been working with eBay on the matter, a company representative said in a statement. "This possible vulnerability was being auctioned on eBay, but has now been removed," the representative said.

According to the description of the item on eBay, the vulnerability was discovered on Dec. 6 and all the details were submitted to Microsoft. The flaw lies in the way Excel validates data when handling documents and exploiting it will compromise a user's PC, according to the now-removed eBay post.

Microsoft is not aware of any attacks that attempt to use the reported vulnerability, the software maker said. The company will continue to investigate the issue and may provide a fix as part of its monthly patching process or issue a security advisory, the Microsoft representative said.

The eBay seller even had a special offer for Microsoft employees: a 10 percent discount. "To qualify, you MUST provide @microsoft.com e-mail address and MUST mention discount code LINUXRULZ during checkout," the now-removed post said.

See more CNET content tagged:
eBay Inc., auction, flaw, Microsoft Excel, vulnerability

Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
THE MIRROR IS HERE
by n3td3v December 9, 2005 10:23 AM PST
http://heapoverflow.com/ebay_joke.htm
Reply to this comment
Talking to vendor via eBay
by n3td3v December 9, 2005 10:27 AM PST
This has been going on for a while, its just that this has been picked up by people, this time round. Theres been causes where a 0-day has been sold to script kids. The vendor never found out about it. I guess this is different, as the offer was talking to the vendor, as well as the wider web.
Reply to this comment
The big picture
by Anonymous1234567890 December 9, 2005 1:11 PM PST
There is something seriously wrong with software when the calculation of maths can render your PC vulnerable. Seriously. Microsoft's work is a joke. This is NOT meant to be an anti-Microsoft post, but this fact can't be sugar-coated: why should editing an Excel document have ANYTHING to do with affecting your PC's general operation? It's insane. Literally.
Reply to this comment
Why buy the cow?
by rcrusoe December 9, 2005 1:13 PM PST
Now if someone came up with an exploit for an IBM iSeries (AS400) THAT might be worth something. As far as I know that platform has never been hacked (other than by "social engineering").

As of last week my McAfee antivirus had over 160,000 Windows virus definitions. Windows security is the ultimate example of an oxymoron.

You can't "swing a dead cat" on the internet without finding a way to break into Windows computers - for free.
Reply to this comment
(4 Comments)
  • prev
  • 1
  • next

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (0.92%) 0.27 29.63
eBay (-0.71%) -0.17 23.74
Dow Jones Industrials (0.72%) 73.00 10,270.47
S&P 500 (0.57%) 6.24 1,093.48
NASDAQ (0.88%) 18.86 2,167.88
CNET TECH (0.63%) 9.86 1,587.17
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right