PT-2011-3526 · Microsoft+1 · Office Excel+1
Publicado
2011-09-15
·
Atualizado
2018-10-12
·
CVE-2011-1986
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel version 2003 SP3
Description
The issue is related to a use-after-free error when processing specially crafted Excel files, allowing remote attackers to execute arbitrary code. Successful exploitation could give an attacker full control over the system, enabling them to install programs, view, modify, or delete data, and create new accounts with full user rights.
Recommendations
For Microsoft Excel 2003 SP3, consider applying security patches or updates that address the use-after-free vulnerability to prevent remote code execution. As a temporary workaround, restrict the opening of Excel files from untrusted sources until a patch is available.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Office Excel
Suse