PT-2010-4110 · Microsoft · Office+2
Damián Frizza
·
Publicado
2010-08-11
·
Atualizado
2018-10-12
·
CVE-2010-2562
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office Excel versions 2002 SP3 through 2003 SP3
Office versions 2004 through 2008 for Mac
Open XML File Format Converter for Mac (affected versions not specified)
Description
The issue arises from improper parsing of the Excel file format, allowing remote attackers to execute arbitrary code or cause a denial of service due to memory corruption via a crafted Excel file. This vulnerability enables an attacker to take complete control of an affected system, potentially leading to the installation of programs, viewing, changing, or deleting data, or creating new accounts with full user rights.
Recommendations
For Microsoft Office Excel versions 2002 SP3 through 2003 SP3, update to a version that properly handles Excel file formats to prevent memory corruption.
For Office versions 2004 through 2008 for Mac, apply the necessary patches or updates to ensure the secure handling of Excel files.
For Open XML File Format Converter for Mac, consider disabling the conversion of Excel files until a patch or update is available to address the memory corruption issue.
Correção
DoS
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Office Excel
Office
Open Xml File Format Converter For Mac