PT-2007-1697 · Microsoft · Excel Viewer 2003+4
Publicado
2007-05-08
·
Atualizado
2018-10-16
·
CVE-2007-0215
CVSS v2.0
7.6
Alta
| Vetor | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel 2000 SP3
Microsoft Excel 2002 SP3
Microsoft Excel 2003 SP2
Microsoft Excel 2003 Viewer
Description
A remote code execution issue exists due to the way Excel handles files with malformed BIFF records. This could be exploited by an attacker constructing a specially crafted Excel file, potentially included in an e-mail attachment or hosted on a malicious website, allowing for remote code execution. The issue arises from a stack-based buffer overflow via a .XLS BIFF file with a malformed Named Graph record, resulting in memory corruption.
Recommendations
For Microsoft Excel 2000 SP3, update to a version that includes the fix for this issue.
For Microsoft Excel 2002 SP3, update to a version that includes the fix for this issue.
For Microsoft Excel 2003 SP2, update to a version that includes the fix for this issue.
For Microsoft Excel 2003 Viewer, update to a version that includes the fix for this issue.
As a temporary workaround, consider avoiding the use of .XLS files from untrusted sources until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Excel 2000
Excel 2002
Excel 2003
Excel Viewer 2003
Office Excel