Microsoft Excel Worksheet Remote Code Execution Vulnerability
BID:22555
Info
Microsoft Excel Worksheet Remote Code Execution Vulnerability
| Bugtraq ID: | 22555 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3029 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2007 12:00AM |
| Updated: | Jul 13 2007 09:46PM |
| Credit: | SehaTo is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Office 2004 for Mac 0 Microsoft Excel 2003 SP3 Microsoft Excel 2003 SP2 Microsoft Excel 2003 SP1 Microsoft Excel 2003 Microsoft Excel 2002 SP3 Microsoft Excel 2002 SP2 Microsoft Excel 2002 SP1 Microsoft Excel 2002 Avaya Customer Interaction Express (CIE) User Interface 1.0.2 Avaya Customer Interaction Express (CIE) User Interface 1.0 Avaya CIE 1.0.2 Avaya CIE 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft Excel Worksheet Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file (.xls).
Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. This may facilitate a compromise of vulnerable computers.
This issue was previously reported as a denial-of-service vulnerability, but has been updated to reflect new information.
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file (.xls).
Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. This may facilitate a compromise of vulnerable computers.
This issue was previously reported as a denial-of-service vulnerability, but has been updated to reflect new information.
Exploit / POC
Microsoft Excel Worksheet Remote Code Execution Vulnerability
A proof of concept is available from the following location; Symantec has not tested the integrity of this proof of concept:
http://securityvulns.com/files/example.xls
A proof of concept is available from the following location; Symantec has not tested the integrity of this proof of concept:
http://securityvulns.com/files/example.xls
Solution / Fix
Microsoft Excel Worksheet Remote Code Execution Vulnerability
Solution:
Microsoft released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Excel 2002 SP3
Microsoft Excel 2003 SP2
Microsoft Office 2004 for Mac 0
Solution:
Microsoft released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Excel 2002 SP3
-
Microsoft Security Update for Excel 2002 (KB936513)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5E09D13B-D4B0 -48FD-9880-73C180570267&displaylang=en
Microsoft Excel 2003 SP2
-
Microsoft Security Update for Excel 2003 (KB936507)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9D93C0CE-5124 -4234-BA84-3C27005E010F&displaylang=en
Microsoft Office 2004 for Mac 0
-
Apple Office2004-1136UpdateEN.dmg
http://download.microsoft.com/download/D/F/9/DF931C33-8A24-48D5-95C3-A 14640A60CB7/Office2004-1136UpdateEN.dmg
References
Microsoft Excel Worksheet Remote Code Execution Vulnerability
References:
References: