PT-2008-4437 · Microsoft · Office+1

Published

2008-08-12

·

Updated

2018-10-30

·

CVE-2008-3005

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office Excel versions 2000 SP3 through 2002 SP3 Microsoft Office 2004 for Mac Microsoft Office 2008 for Mac
Description A remote code execution issue exists in the way Excel processes an array index when loading Excel files into memory. An attacker could exploit this by opening a specially crafted file, which could be hosted on a Web site or included as an e-mail attachment.
Recommendations For Microsoft Office Excel 2000 SP3, update to a newer version to mitigate the risk. For Microsoft Office Excel 2002 SP3, update to a newer version to mitigate the risk. For Microsoft Office 2004 for Mac, update to a newer version to mitigate the risk. For Microsoft Office 2008 for Mac, update to a newer version to mitigate the risk.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3005

Affected Products

Office
Office Excel