PT-2007-1697 · Microsoft · Excel Viewer 2003+4

Publicado

2007-05-08

·

Atualizado

2018-10-16

·

CVE-2007-0215

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Excel 2000 SP3 Microsoft Excel 2002 SP3 Microsoft Excel 2003 SP2 Microsoft Excel 2003 Viewer
Description A remote code execution issue exists due to the way Excel handles files with malformed BIFF records. This could be exploited by an attacker constructing a specially crafted Excel file, potentially included in an e-mail attachment or hosted on a malicious website, allowing for remote code execution. The issue arises from a stack-based buffer overflow via a .XLS BIFF file with a malformed Named Graph record, resulting in memory corruption.
Recommendations For Microsoft Excel 2000 SP3, update to a version that includes the fix for this issue. For Microsoft Excel 2002 SP3, update to a version that includes the fix for this issue. For Microsoft Excel 2003 SP2, update to a version that includes the fix for this issue. For Microsoft Excel 2003 Viewer, update to a version that includes the fix for this issue. As a temporary workaround, consider avoiding the use of .XLS files from untrusted sources until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0215

Produtos afetados

Excel 2000
Excel 2002
Excel 2003
Excel Viewer 2003
Office Excel