English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Microsoft Office Excel Multiple Vulnerabilities


Secunia ID

SA38805

CVE-ID

CVE-2010-0257, CVE-2010-0258, CVE-2010-0260, CVE-2010-0261, CVE-2010-0262, CVE-2010-0263, CVE-2010-0264

Release Date

09 Mar 2010

Last Change

10 Mar 2010

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Microsoft Excel 2002
Microsoft Excel 2003
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2004 for Mac
Microsoft Office 2007
Microsoft Office 2008 for Mac
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Excel 2007
Microsoft Office Excel Viewer 2007
Microsoft Office SharePoint Server 2007
Microsoft Office XP
Microsoft Open XML File Format Converter for Mac

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

Multiple vulnerabilities have been reported in Microsoft Office Excel, which can be exploited by malicious people to compromise a user's system.

1) An error in the parsing of records can be exploited to corrupt memory via a specially crafted file.

2) An error in the parsing of sheet object types can be exploited to corrupt memory via a specially crafted file.

3) An error in the parsing of MDXTUPLE records can be exploited to cause a heap-based buffer overflow via a specially crafted file.

4) An error in the parsing of MDXSET records can be exploited to cause a heap-based buffer overflow via a specially crafted file.

5) An error in the parsing of FNGROUPNAME records may result in the use of uninitialised memory via a specially crafted file.

6) An error in the parsing of a ZIP header within XLSX files when decompressing certain XML elements may result in use of uninitialised memory.

7) An error in the parsing of DbOrParamQry records can be exploited to corrupt memory via a specially crafted file.

Successful exploitation of the vulnerabilities may allow execution of arbitrary code.

Solution

Apply patches.

Microsoft Office Excel 2002 SP3:
http://www.microsoft.com/downloads/details.aspx?familyid=E0136F62-60CE-4EBD-8660-BE81EBA29AE8

Microsoft Office Excel 2003 SP3:
http://www.microsoft.com/downloads/details.aspx?familyid=7E42793E-747B-48DA-968A-1EC29EA37151

Microsoft Office Excel 2007 SP1:
http://www.microsoft.com/downloads/details.aspx?familyid=03429F8A-8AAB-4A59-97E4-7CE047F100A5

Microsoft Office Excel 2007 SP2:
http://www.microsoft.com/downloads/details.aspx?familyid=03429F8A-8AAB-4A59-97E4-7CE047F100A5

Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyID=ae5936f8-fe3f-4d23-a37c-d80f228e475e

Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyID=e0ed1569-ab2f-407c-b728-4eddc463c385

Open XML File Format Converter for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyID=4c5487d5-c912-4087-8c83-769e3fb78ea9

Microsoft Office Excel Viewer SP1/SP2:
http://www.microsoft.com/downloads/details.aspx?familyid=010D0A4D-02A4-4142-963B-A38CD06CC897

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1/SP2:
http://www.microsoft.com/downloads/details.aspx?familyid=314F076E-8F9D-46C2-B666-86599A02BF15

Microsoft Office SharePoint Server 2007 SP1 (32-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=94DDF6EF-3392-4D77-A02B-3BC0470721CD

Microsoft Office SharePoint Server 2007 SP2 (32-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=94DDF6EF-3392-4D77-A02B-3BC0470721CD

Microsoft Office SharePoint Server 2007 SP1 (64-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=06F6BFFB-3FAD-4FB5-878B-39550812E9B5

Microsoft Office SharePoint Server 2007 SP2 (64-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=06F6BFFB-3FAD-4FB5-878B-39550812E9B5

NOTE: Some links may not currently work as this advisory was rushed since information about the upcoming Microsoft security bulletins was purposefully leaked by a third party.

Reported by

1) The vendor credits Nicolas Joly, Vupen.
2-5) Sean Larsson, VeriSign iDefense Labs.
6) An anonymous person via ZDI.
7) The vendor credits Damián Frizza, Core Security Technologies.

Original Advisory

MS10-017 (KB980150, KB978471, KB978474, KB978382, KB980837, KB980839, KB980840, KB978383, KB978380, KB979439):
http://www.microsoft.com/technet/security/bulletin/ms10-017.mspx

iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=859
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=860
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=861
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=862

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-10-025/

Core Security:
http://www.coresecurity.com/content/CORE-2009-1103