Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Microsoft Excel Could Allow Remote Code Execution Vulnerabilities (954066)

Information

Severity

Severity

Critical

Family

Family

Windows : Microsoft Bulletins

CVSSv2 Base

CVSSv2 Base

9.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

15 years ago

Modified

Modified

4 years ago

Summary

This host is missing critical security update according to Microsoft Bulletin MS08-043.

Insight

Insight

Multiple flaw are due to, - index values are not properly validated when loading Excel files into memory. - an errors during processing/parsing of certain array indexes and record values when loading Excel files into memory. - a password strings to remote data sources are not being properly deleted even when configured to not store credentials.

Affected Software

Affected Software

Microsoft Excel 2002/XP/2003/2007 on Windows (All). Microsoft Excel Viewer 2003/2007 on Windows (All).

Solution

Solution

The vendor has released updates. Please see the references for more information.

Common Vulnerabilities and Exposures (CVE)