PT-2010-4110 · Microsoft · Office+2
Damián Frizza
·
Published
2010-08-11
·
Updated
2018-10-12
·
CVE-2010-2562
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office Excel versions 2002 SP3 through 2003 SP3
Office versions 2004 through 2008 for Mac
Open XML File Format Converter for Mac (affected versions not specified)
Description
The issue arises from improper parsing of the Excel file format, allowing remote attackers to execute arbitrary code or cause a denial of service due to memory corruption via a crafted Excel file. This vulnerability enables an attacker to take complete control of an affected system, potentially leading to the installation of programs, viewing, changing, or deleting data, or creating new accounts with full user rights.
Recommendations
For Microsoft Office Excel versions 2002 SP3 through 2003 SP3, update to a version that properly handles Excel file formats to prevent memory corruption.
For Office versions 2004 through 2008 for Mac, apply the necessary patches or updates to ensure the secure handling of Excel files.
For Open XML File Format Converter for Mac, consider disabling the conversion of Excel files until a patch or update is available to address the memory corruption issue.
Fix
DoS
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Excel
Office
Open Xml File Format Converter For Mac