Home→Descriptions→SA28506
| Secunia ID | |
| CVE-ID |
CVE-2008-0081, CVE-2008-0111, CVE-2008-0112, CVE-2008-0114, CVE-2008-0115, CVE-2008-0116, CVE-2008-0117 |
| Release Date |
16 Jan 2008 |
| Last Change |
14 Mar 2008 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Microsoft Excel 2000 |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
Multiple vulnerabilities have been reported in Microsoft Excel, which can be exploited by malicious people to compromise a user's system. 1) An error in the handling of macros can be exploited via a specially crafted Excel file to execute arbitrary code. NOTE: According to Microsoft, this vulnerability is currently being actively exploited. 2) An error when processing data validation (DVAL) records can be exploited to corrupt memory via a specially crafted Excel file. 3) An error when importing files into Excel can be exploited via a specially crafted .slk file. 4) An error in the handling of style records can be exploited to corrupt memory via a specially crafted Excel file. 5) An error in the parsing of formulas can be exploited to corrupt memory via a specially crafted Excel file. 6) An error in the handling of rich text values can be exploited via a specially crafted Excel file. 7) An error in the handling of conditional formatting values can be exploited via a specially crafted Excel file. Successful exploitation of the vulnerabilities may allow execution of arbitrary code. |
| Solution |
Apply patches. Excel 2000 SP3: Excel 2002 SP3: Excel 2003 SP2: Excel 2007: Microsoft Office Excel Viewer 2003: Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats: Microsoft Office 2004 for Mac: Microsoft Office 2008 for Mac: |
| Reported by |
1) Discovered as a 0-day. The vendor also credits Matt Richard, VeriSign. |
| Original Advisory |
MS08-014 (KB949029): Microsoft (KB947563): iDefense Labs: TippingPoint DVLabs: |