PT-2008-4437 · Microsoft · Office+1
Published
2008-08-12
·
Updated
2018-10-30
·
CVE-2008-3005
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office Excel versions 2000 SP3 through 2002 SP3
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Description
A remote code execution issue exists in the way Excel processes an array index when loading Excel files into memory. An attacker could exploit this by opening a specially crafted file, which could be hosted on a Web site or included as an e-mail attachment.
Recommendations
For Microsoft Office Excel 2000 SP3, update to a newer version to mitigate the risk.
For Microsoft Office Excel 2002 SP3, update to a newer version to mitigate the risk.
For Microsoft Office 2004 for Mac, update to a newer version to mitigate the risk.
For Microsoft Office 2008 for Mac, update to a newer version to mitigate the risk.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office
Office Excel