Microsoft Excel Malformed Column Record Remote Code Execution Vulnerability
BID:21925
Info
Microsoft Excel Malformed Column Record Remote Code Execution Vulnerability
| Bugtraq ID: | 21925 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0030 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2007 12:00AM |
| Updated: | Jun 04 2007 11:10PM |
| Credit: | Greg MacManus of IDefense Labs is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Works Suite 2006 0 Microsoft Works Suite 2005 0 Microsoft Works Suite 2004 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 Microsoft Excel x for Mac 0 Microsoft Excel Viewer 2003 0 Microsoft Excel 2004 for Mac 0 Microsoft Excel 2003 SP2 Microsoft Excel 2003 SP1 Microsoft Excel 2003 Microsoft Excel 2002 SP3 Microsoft Excel 2002 SP2 Microsoft Excel 2002 SP1 Microsoft Excel 2002 Microsoft Excel 2000 SP3 Microsoft Excel 2000 SP2 Microsoft Excel 2000 0 Microsoft Excel 0 |
| Not Vulnerable: | |
Discussion
Microsoft Excel Malformed Column Record Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
An attacker could exploit this issue to execute arbitrary code with the privileges of the user running the application. The attacker could leverage the issue to compromise affected computers.
Microsoft Excel is prone to a remote code-execution vulnerability.
An attacker could exploit this issue to execute arbitrary code with the privileges of the user running the application. The attacker could leverage the issue to compromise affected computers.
Exploit / POC
Microsoft Excel Malformed Column Record Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Microsoft Excel Malformed Column Record Remote Code Execution Vulnerability
Solution:
Microsoft has released a fix to address this issue. Please see the references section for more information.
Update: Microsoft has re-released MS07-002 to resolve a regression with the original Excel 2000 fixes when dealing with files created when in Korean, Chinese, or Japanese executable modes. Please see the knowledge base article (KB931183) for further information.
Microsoft Works Suite 2005 0
Microsoft Office 2000 SP3
Microsoft Excel 2003
Microsoft Works Suite 2004
Microsoft Excel 2000 SP3
Microsoft Excel Viewer 2003 0
Solution:
Microsoft has released a fix to address this issue. Please see the references section for more information.
Update: Microsoft has re-released MS07-002 to resolve a regression with the original Excel 2000 fixes when dealing with files created when in Korean, Chinese, or Japanese executable modes. Please see the knowledge base article (KB931183) for further information.
Microsoft Works Suite 2005 0
-
Microsoft KB925523 - Security Update for Excel 2002, Microsoft Works Suite 2004, Microsoft Works Suite 2005
Security Update for Excel 2002, Microsoft Works Suite 2004 and Microsoft Works Suite 2005 (KB925523)
http://www.microsoft.com/downloads/details.aspx?familyid=EE7278EA-3AEE -4994-9657-66019961D63C&displaylang=en
Microsoft Office 2000 SP3
-
Microsoft Security Update for Excel 2000 (KB925524)
http://www.microsoft.com/downloads/details.aspx?familyid=5CCF4455-6B22 -4249-93D7-661D12839292
Microsoft Excel 2003
-
Microsoft KB925257 - Security Update for Excel 2003
Security Update for Excel 2003 (KB925257)
http://www.microsoft.com/downloads/details.aspx?familyid=79B88CE8-5C56 -462F-AC1A-4BCE04C8F543&displaylang=en -
Microsoft KB925523 - Security Update for Excel 2002, Microsoft Works Suite 2004, Microsoft Works Suite 2005
Security Update for Excel 2002, Microsoft Works Suite 2004 and Microsoft Works Suite 2005 (KB925523)
http://www.microsoft.com/downloads/details.aspx?familyid=EE7278EA-3AEE -4994-9657-66019961D63C&displaylang=en
Microsoft Works Suite 2004
-
Microsoft KB925523 - Security Update for Excel 2002, Microsoft Works Suite 2004, Microsoft Works Suite 2005
Security Update for Excel 2002, Microsoft Works Suite 2004 and Microsoft Works Suite 2005 (KB925523)
http://www.microsoft.com/downloads/details.aspx?familyid=EE7278EA-3AEE -4994-9657-66019961D63C&displaylang=en
Microsoft Excel 2000 SP3
-
Microsoft Security Update for Excel 2000 (KB925524)
http://www.microsoft.com/downloads/details.aspx?familyid=5CCF4455-6B22 -4249-93D7-661D12839292
Microsoft Excel Viewer 2003 0
-
Microsoft KB925525 - Security Update for Excel Viewer 2003
Security Update for Excel Viewer 2003 (KB925525)
http://www.microsoft.com/downloads/details.aspx?familyid=99AE7653-F0FD -4DBA-A151-098FD03E6EA4&displaylang=en
References
Microsoft Excel Malformed Column Record Remote Code Execution Vulnerability
References:
References:
- 925524 - Description of the security update for Excel 2000: January 9, 2007 (Microsoft)
- 931183 - Excel 2000 does not open some files after you install security update 9 (Microsoft)
- Microsoft Office Product Homepage (Microsoft)
- Re-release of Security Bulletin MS07-002 resolves issue of Excel 2000 not openin (Microsoft)
- Microsoft Excel Invalid Column Heap Corruption Vulnerability] (iDefense Labs)
- Centrex IP Client Manager (CICM) response to Microsoft January securit (Nortel Networks)
- MS07-002 (Microsoft)