PT-2011-3526 · Microsoft+1 · Office Excel+1
Published
2011-09-15
·
Updated
2018-10-12
·
CVE-2011-1986
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel version 2003 SP3
Description
The issue is related to a use-after-free error when processing specially crafted Excel files, allowing remote attackers to execute arbitrary code. Successful exploitation could give an attacker full control over the system, enabling them to install programs, view, modify, or delete data, and create new accounts with full user rights.
Recommendations
For Microsoft Excel 2003 SP3, consider applying security patches or updates that address the use-after-free vulnerability to prevent remote code execution. As a temporary workaround, restrict the opening of Excel files from untrusted sources until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Excel
Suse