Description: | Summary: This host is missing a critical security update according to Microsoft Bulletin MS10-080.
Vulnerability Insight: The flaws are due to:
- An integer overflow error when processing record information
- A memory corruption error when processing malformed records
- A memory corruption error when processing malformed Lotus 1-2-3 workbook (.wk3) file.
- A memory corruption error when processing malformed formula information
- A memory corruption error when processing malformed formula BIFF records
- An out-of-bounds array when processing malformed records
- An invalid pointer when processing malformed Merge Cell records.
- A memory corruption error when processing negative future functions
- An out-of-boundary access when processing malformed records
- An array indexing error when processing malformed Real Time Data records
- An out-of-bounds memory write when processing malformed data
- A memory corruption error when processing malformed Ghost records
Vulnerability Impact: Successful exploitation could allow attackers to execute arbitrary code by tricking a user into opening a malicious Excel file.
Affected Software/OS: - Microsoft Excel Viewer Service Pack 2
- Microsoft Office Excel 2002 Service Pack 3
- Microsoft Office Excel 2003 Service Pack 3
- Microsoft Office Excel 2007 Service Pack 2
- Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|