PT-2008-1771 · Microsoft · Office Excel+3

Publicado

2008-03-11

·

Atualizado

2018-10-15

·

CVE-2008-0116

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Excel versions 2000 SP3 through 2003 SP2 Microsoft Excel Viewer 2003 Microsoft Office Compatibility Pack Microsoft Office 2004 for Mac Microsoft Office 2008 for Mac
Description A remote code execution issue exists due to the handling of rich text values when loading application data into memory. An attacker could exploit this by sending a malformed file, which could be hosted on a specially crafted or compromised web site, or included as an email attachment.
Recommendations For Microsoft Excel versions 2000 SP3 through 2003 SP2, consider avoiding the use of rich text values until a patch is available. For Microsoft Excel Viewer 2003, restrict access to malformed files to minimize the risk of exploitation. For Microsoft Office Compatibility Pack, avoid using the pack to open potentially malicious files until the issue is resolved. For Microsoft Office 2004 and 2008 for Mac, refrain from opening attachments or files from untrusted sources that could contain malformed rich text values.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0116

Produtos afetados

Office Excel
Excel Viewer
Office
Office Compatibility Pack