.xll file extension = A malicious attack using abusing the XLL File starts with the delivery of a malicious file with the extension "XLL"
Categories
(Firefox :: File Handling, defect)
Tracking
()
People
(Reporter: Puf, Assigned: mak)
Details
(4 keywords, Whiteboard: [reporter-external] [client-bounty-form] [verif?] [adv-main117+] [adv-esr115.2+] [adv-esr102.15+])
Attachments
(5 files, 2 obsolete files)
104.85 KB,
video/mp4
|
Details | |
48 bytes,
text/x-phabricator-request
|
Details | Review | |
48 bytes,
text/x-phabricator-request
|
RyanVM
:
approval-mozilla-esr115+
|
Details | Review |
48 bytes,
text/x-phabricator-request
|
RyanVM
:
approval-mozilla-esr102+
|
Details | Review |
255 bytes,
text/plain
|
Details |
Firefox Version: [116.0b5] + [117.0a1]
Operating System: [Windows 10] (64-bit)
.xll = An XLL file is an add-in used by Microsoft Excel
It is the Excel Add-In file, that provides a way to use third-party tools and functions within Microsoft Excel. The third-party code can be C/C++ .NET code inside the Excel environment. In fact, despite the Excel icon, the XLL file is a Dynamic Linked Library, a binary executable file.
Cisco Talos investigates another vector for introduction of malicious code to Microsoft Excel—malicious add-ins, specifically XLL files.
.xll Blocked In Outlook Attachment
This File is Already Blocklisted in Chrome & Edge Browsers
The researchers are saying this technique is Xll particularly dangerous because the victims only need one click to compromise their endpoints.
This File is Already Blocklisted in Chrome & Edge Browsers
it's better to Add Popop Warning [ Executable files may contain viruses or other malicious code that could harm your computer]
To .xll file To Keep Safe System from malicious file/code
Reporter | ||
Comment 1•2 years ago
|
||
Step To Reproduce:
- Create .xll File.
- Download Using Firefox Browser
- Open File [No Warning] In Firefox Browser
Reporter | ||
Comment 2•2 years ago
|
||
file_types {
DLL files built for excel.
extension: "xll"
platform_settings {
platform: PLATFORM_TYPE_WINDOWS
danger_level: ALLOW_ON_USER_GESTURE
auto_open_hint: DISALLOW_AUTO_OPEN
}
}
Reporter | ||
Comment 3•2 years ago
|
||
Updated•2 years ago
|
Comment 4•2 years ago
|
||
"xll" is in our safebrowsing download reputation checks, but of course that won't catch any kind of targeted or even low-volume malicious file.
Comment 5•2 years ago
|
||
Confirmed that this is not in our executable list, if we decide that we need to police this. Supposedly MS is going to add a warning prompt for these to protect people, but 1) people won't update their Excell very quickly, and 2) A similar warning for Word macros didn't full help solve that problem. Maybe we do need to worry about these, also.
Assignee | ||
Updated•2 years ago
|
Comment 6•2 years ago
|
||
Clearing my needinfo given Marco has graciously agreed to pick this up (thank you!)
Assignee | ||
Comment 7•2 years ago
|
||
![]() |
||
Comment 9•2 years ago
|
||
Assignee | ||
Comment 10•2 years ago
|
||
Updated•2 years ago
|
Comment 11•2 years ago
|
||
Uplift Approval Request
- Needs manual QE test: yes
- Fix verified in Nightly: no
- Explanation of risk level: adding to a blocklist
- Risk associated with taking this patch: low
- String changes made/needed: none
- Steps to reproduce for manual QE testing: Try downloading a xll file. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately opening Excel
- Code covered by automated testing: yes
- User impact if declined: sec-moderate
- Is Android affected?: no
Updated•2 years ago
|
Assignee | ||
Comment 12•2 years ago
|
||
Comment 13•2 years ago
|
||
Uplift Approval Request
- User impact if declined: sec-moderate
- Is Android affected?: no
- Explanation of risk level: just adding to a blocklist
- Fix verified in Nightly: no
- Code covered by automated testing: yes
- String changes made/needed: none
- Risk associated with taking this patch: low
- Steps to reproduce for manual QE testing: Try downloading a xll file. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately opening Excel
- Needs manual QE test: yes
Updated•2 years ago
|
Updated•2 years ago
|
Assignee | ||
Comment 14•2 years ago
|
||
Comment 15•2 years ago
|
||
Uplift Approval Request
- Fix verified in Nightly: no
- Explanation of risk level: adding to a blocklist
- String changes made/needed: none
- Risk associated with taking this patch: low
- Code covered by automated testing: yes
- Steps to reproduce for manual QE testing: Try downloading a xll file. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately opening Excel
- Needs manual QE test: yes
- User impact if declined: sec-moderate
- Is Android affected?: no
Assignee | ||
Updated•2 years ago
|
Assignee | ||
Comment 16•2 years ago
|
||
Comment 17•2 years ago
|
||
Uplift Approval Request
- User impact if declined: sec-moderate - Can ride along an RC or dot
- Is Android affected?: no
- String changes made/needed: none
- Risk associated with taking this patch: low
- Code covered by automated testing: yes
- Steps to reproduce for manual QE testing: Try downloading a xll file. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately opening Excel
- Fix verified in Nightly: no
- Explanation of risk level: adding to a blocklist
- Needs manual QE test: yes
Updated•2 years ago
|
Comment 18•2 years ago
|
||
Since this bug didn't have a rating it should have requested sec-approval before landing. Please see the guidelines at the "Approval Process" link in the yellow "security bug banner" above.
Updated•2 years ago
|
Assignee | ||
Comment 19•2 years ago
|
||
(In reply to Daniel Veditz [:dveditz] from comment #18)
Since this bug didn't have a rating it should have requested sec-approval before landing.
I'm sorry about that, it was my fault. I had the other similar recent bug in mind and didn't pay attention to the lack of rating here.
Comment 20•2 years ago
|
||
Comment on attachment 9345805 [details]
Bug 1843758.
Approved for 115.2esr.
Comment 21•2 years ago
|
||
Comment on attachment 9345966 [details]
Bug 1843758.
Approved for 102.15esr.
Comment 22•2 years ago
|
||
uplift |
Updated•2 years ago
|
Comment 23•2 years ago
|
||
uplift |
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Comment 24•2 years ago
|
||
Reproduced the initial issue using an old Nightly build from 2023-07-16, verified that using latest Firefox Beta 117.0b3, latest Firefox 115esr and 102esr from treeherder on Windows 10 and Windows 11 that this is now fixed, we now display the notification after downloading and accessing a .xll file.
Is this fix only for Windows?
I am convinced that this is a Windows only fix but I had to check if this is also for Mac or Linux, I saw that Excel is also available for mac (no notification message for mac on the builds fixed here) but not sure if the format .xll is something for mac and if a malicious .xll on mac can do the same thing as on Windows so I had to ask.
Assignee | ||
Comment 25•2 years ago
•
|
||
It is technically possible to develop an .xll file for Excel on Linux (And I suspect Unix in general), but it requires specially crafted code for excel to load it. It's also a lot less likely for users on that platform to have Excel installed. So the impact would be not significant.
Also executable files definition on Unix systems is different, as it doesn't just depend on the file extension.
So I don't think it's worth spending time on those verifications on Unix.
Comment 26•2 years ago
|
||
(In reply to Marco Bonardo [:mak] from comment #25)
It is technically possible to develop an .xll file for Excel on Linux (And I suspect Unix in general), but it requires specially crafted code for excel to load it. It's also a lot less likely for users on that platform to have Excel installed. So the impact would be not significant.
Also executable files definition on Unix systems is different, as it doesn't just depend on the file extension.
So I don't think it's worth spending time on those verifications on Unix.
Thanks Marco for the info, based on the above I am going to close this as VERIFIED FIXED.
Updated•1 years ago
|
Updated•1 years ago
|
Comment 27•1 years ago
|
||
Updated•1 years ago
|
Updated•1 year ago
|
Updated•1 year ago
|
Updated•8 months ago
|
Description
•