PT-2008-1772 · Microsoft · Office Excel+1
Dan Hubbard
+1
·
Published
2008-03-11
·
Updated
2018-10-12
·
CVE-2008-0117
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel versions 2000 SP3 and 2002 SP2
Microsoft Office versions 2004 and 2008 for Mac
Description
The issue allows remote attackers to execute arbitrary code via crafted conditional formatting values. A remote code execution vulnerability exists in the way Excel handles conditional formatting values. An attacker could exploit the vulnerability by sending a malformed file which could be hosted on a specially crafted or compromised Web site, or included as an e-mail attachment.
Recommendations
For Microsoft Excel 2000 SP3, update to a version that is not affected by this issue.
For Microsoft Excel 2002 SP2, update to a version that is not affected by this issue.
For Microsoft Office 2004 for Mac, update to a version that is not affected by this issue.
For Microsoft Office 2008 for Mac, update to a version that is not affected by this issue.
As a temporary workaround, consider avoiding the use of conditional formatting values in Excel until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Excel
Office