PT-2008-1736 · Microsoft · Office Excel+2

Published

2008-01-16

·

Updated

2025-01-17

·

CVE-2008-0081

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Excel versions 2000 SP3 through 2003 SP2 Microsoft Excel Viewer 2003 Microsoft Office 2004 for Mac
Description The issue allows user-assisted remote attackers to execute arbitrary code via crafted macros. A remote code execution vulnerability exists in the way Excel handles macros when opening specially crafted Excel files. An attacker could exploit the vulnerability by sending a malformed file which could be hosted on a specially crafted or compromised Web site, or included as an e-mail attachment.
Recommendations For Microsoft Excel versions 2000 SP3 through 2003 SP2, consider disabling macro execution until a patch is available. For Microsoft Excel Viewer 2003, restrict access to specially crafted Excel files to minimize the risk of exploitation. For Microsoft Office 2004 for Mac, avoid opening Excel files from untrusted sources until the issue is resolved.

Exploit

Fix

RCE

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

CVE-2008-0081

Affected Products

Office Excel
Excel Viewer
Office