PT-2007-6821 · Microsoft+1 · Office+2
Published
2007-12-19
·
Updated
2017-07-29
·
CVE-2007-5861
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X version 10.4.11
Description
The issue is related to an unspecified vulnerability in Spotlight, which can be triggered by a crafted .XLS file. This can cause memory corruption in the Microsoft Office Spotlight Importer, leading to either a denial of service (application termination) or the execution of arbitrary code.
Recommendations
For Apple Mac OS X version 10.4.11, consider avoiding the use of crafted .XLS files to prevent potential exploitation until a fix is available. As a temporary workaround, restrict access to the Microsoft Office Spotlight Importer to minimize the risk of arbitrary code execution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Macos X
Office
Office Spotlight Importer