Microsoft Excel Malformed Palette Record Remote Code Execution Vulnerability
BID:21922
Info
Microsoft Excel Malformed Palette Record Remote Code Execution Vulnerability
| Bugtraq ID: | 21922 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0031 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2007 12:00AM |
| Updated: | Feb 01 2007 05:58PM |
| Credit: | Greg MacManus of IDefense Labs discovered this issue. |
| Vulnerable: |
Microsoft Works Suite 2006 0 Microsoft Works Suite 2005 0 Microsoft Works Suite 2004 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 Microsoft Excel x for Mac 0 Microsoft Excel Viewer 2003 0 Microsoft Excel 2004 for Mac 0 Microsoft Excel 2003 SP2 Microsoft Excel 2003 SP1 Microsoft Excel 2003 Microsoft Excel 2002 SP3 Microsoft Excel 2002 SP2 Microsoft Excel 2002 SP1 Microsoft Excel 2002 Microsoft Excel 2000 SP3 Microsoft Excel 2000 SP2 Microsoft Excel 2000 0 Microsoft Excel 0 |
| Not Vulnerable: | |
Discussion
Microsoft Excel Malformed Palette Record Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application, which can result in the compromise of affected computers.
Microsoft Excel is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application, which can result in the compromise of affected computers.
Exploit / POC
Microsoft Excel Malformed Palette Record Remote Code Execution Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Microsoft Excel Malformed Palette Record Remote Code Execution Vulnerability
Solution:
Microsoft has released a fix to address this issue. Please see the references for more information.
Update: Microsoft has re-released MS07-002 to resolve a regression with the original Excel 2000 fixes when dealing with files created when in Korean, Chinese, or Japanese executable modes. Please see the knowledge base article (KB931183) for more information.
Microsoft Works Suite 2005 0
Microsoft Office 2000 SP3
Microsoft Excel 2003
Microsoft Works Suite 2004
Microsoft Excel 2000 SP3
Microsoft Excel Viewer 2003 0
Solution:
Microsoft has released a fix to address this issue. Please see the references for more information.
Update: Microsoft has re-released MS07-002 to resolve a regression with the original Excel 2000 fixes when dealing with files created when in Korean, Chinese, or Japanese executable modes. Please see the knowledge base article (KB931183) for more information.
Microsoft Works Suite 2005 0
-
Microsoft KB925523 - Security Update for Excel 2002, Microsoft Works Suite 2004, Microsoft Works Suite 2005
Security Update for Excel 2002, Microsoft Works Suite 2004 and Microsoft Works Suite 2005 (KB925523)
http://www.microsoft.com/downloads/details.aspx?familyid=EE7278EA-3AEE -4994-9657-66019961D63C&displaylang=en
Microsoft Office 2000 SP3
-
Microsoft Security Update for Excel 2000 (KB925524)
http://www.microsoft.com/downloads/details.aspx?familyid=5CCF4455-6B22 -4249-93D7-661D12839292
Microsoft Excel 2003
-
Microsoft KB925257 - Security Update for Excel 2003
Security Update for Excel 2003 (KB925257)
http://www.microsoft.com/downloads/details.aspx?familyid=79B88CE8-5C56 -462F-AC1A-4BCE04C8F543&displaylang=en -
Microsoft KB925523 - Security Update for Excel 2002, Microsoft Works Suite 2004, Microsoft Works Suite 2005
Security Update for Excel 2002, Microsoft Works Suite 2004 and Microsoft Works Suite 2005 (KB925523)
http://www.microsoft.com/downloads/details.aspx?familyid=EE7278EA-3AEE -4994-9657-66019961D63C&displaylang=en
Microsoft Works Suite 2004
-
Microsoft KB925523 - Security Update for Excel 2002, Microsoft Works Suite 2004, Microsoft Works Suite 2005
Security Update for Excel 2002, Microsoft Works Suite 2004 and Microsoft Works Suite 2005 (KB925523)
http://www.microsoft.com/downloads/details.aspx?familyid=EE7278EA-3AEE -4994-9657-66019961D63C&displaylang=en
Microsoft Excel 2000 SP3
-
Microsoft Security Update for Excel 2000 (KB925524)
http://www.microsoft.com/downloads/details.aspx?familyid=5CCF4455-6B22 -4249-93D7-661D12839292
Microsoft Excel Viewer 2003 0
-
Microsoft KB925525 - Security Update for Excel Viewer 2003
Security Update for Excel Viewer 2003 (KB925525)
http://www.microsoft.com/downloads/details.aspx?familyid=99AE7653-F0FD -4DBA-A151-098FD03E6EA4&displaylang=en