Microsoft Excel Filter Records Remote Code Execution Vulnerability
BID:23780
Info
Microsoft Excel Filter Records Remote Code Execution Vulnerability
| Bugtraq ID: | 23780 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1214 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2007 12:00AM |
| Updated: | May 18 2007 06:18PM |
| Credit: | Greg MacManus of iDefense Labs is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Excel Viewer 2003 0 Microsoft Excel 2004 for Mac 0 Microsoft Excel 2003 SP3 Microsoft Excel 2003 SP2 Microsoft Excel 2003 SP1 Microsoft Excel 2003 Microsoft Excel 2002 SP3 Microsoft Excel 2002 SP2 Microsoft Excel 2002 SP1 Microsoft Excel 2002 Microsoft Excel 2000 SR1 Microsoft Excel 2000 SP3 Microsoft Excel 2000 SP2 Microsoft Excel 2000 0 Avaya CIE 1.0 |
| Not Vulnerable: |
Microsoft Excel 2007 0 |
Discussion
Microsoft Excel Filter Records Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of a victim user running the application. A successful exploit will result in the compromise of the application and may aid in further attacks.
Microsoft Excel is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of a victim user running the application. A successful exploit will result in the compromise of the application and may aid in further attacks.
Exploit / POC
Microsoft Excel Filter Records Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Microsoft Excel Filter Records Remote Code Execution Vulnerability
Solution:
Microsoft has released a security advisory and fixes to address this issue. Please see the references for more information.
KB934233 has been updated to inform users of a potential problem with the installation of fixes. Fixes may not have been successfully installed if either Microsoft Update or Microsoft Windows Server Update Services were used to install fixes on Microsoft Vista computers running Office 2007. Please see the references for more information about this issue.
Microsoft Excel 2002 SP3
Microsoft Excel 2003 SP2
Microsoft Excel 2000 0
Microsoft Excel 2002 SP1
Microsoft Excel 2003 SP1
Microsoft Excel 2002
Microsoft Excel 2003 SP3
Microsoft Excel 2000 SP3
Microsoft Excel 2002 SP2
Microsoft Excel 2000 SP2
Microsoft Excel Viewer 2003 0
Microsoft Excel 2003
Solution:
Microsoft has released a security advisory and fixes to address this issue. Please see the references for more information.
KB934233 has been updated to inform users of a potential problem with the installation of fixes. Fixes may not have been successfully installed if either Microsoft Update or Microsoft Windows Server Update Services were used to install fixes on Microsoft Vista computers running Office 2007. Please see the references for more information about this issue.
Microsoft Excel 2002 SP3
-
Microsoft KB934453 - Security Update for Excel 2002
http://www.microsoft.com/downloads/details.aspx?FamilyId=29596861-D9F0 -4A10-9E1C-CDA75DDE017D
Microsoft Excel 2003 SP2
-
Microsoft KB933666 - Security Update for Excel 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=9567C583-556F -4379-80BA-3E0C8993C04C
Microsoft Excel 2000 0
-
Microsoft KB934447 - Security Update for Excel 2000
http://www.microsoft.com/downloads/details.aspx?FamilyId=5F101D03-C0A7 -41E0-95A4-A12AFB356D5F
Microsoft Excel 2002 SP1
-
Microsoft KB934453 - Security Update for Excel 2002
http://www.microsoft.com/downloads/details.aspx?FamilyId=29596861-D9F0 -4A10-9E1C-CDA75DDE017D
Microsoft Excel 2003 SP1
-
Microsoft KB933666 - Security Update for Excel 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=9567C583-556F -4379-80BA-3E0C8993C04C
Microsoft Excel 2002
-
Microsoft KB934453 - Security Update for Excel 2002
http://www.microsoft.com/downloads/details.aspx?FamilyId=29596861-D9F0 -4A10-9E1C-CDA75DDE017D
Microsoft Excel 2003 SP3
-
Microsoft KB933666 - Security Update for Excel 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=9567C583-556F -4379-80BA-3E0C8993C04C
Microsoft Excel 2000 SP3
-
Microsoft KB934447 - Security Update for Excel 2000
http://www.microsoft.com/downloads/details.aspx?FamilyId=5F101D03-C0A7 -41E0-95A4-A12AFB356D5F
Microsoft Excel 2002 SP2
-
Microsoft KB934453 - Security Update for Excel 2002
http://www.microsoft.com/downloads/details.aspx?FamilyId=29596861-D9F0 -4A10-9E1C-CDA75DDE017D
Microsoft Excel 2000 SP2
-
Microsoft KB934447 - Security Update for Excel 2000
http://www.microsoft.com/downloads/details.aspx?FamilyId=5F101D03-C0A7 -41E0-95A4-A12AFB356D5F
Microsoft Excel Viewer 2003 0
-
Microsoft KB934445 - Security Update for Excel Viewer 2003
http://www.microsoft.com/downloads/details.aspx?familyid=3C7F18AC-24BB -41CF-B8DA-997706FDC44C&displaylang=en
Microsoft Excel 2003
-
Microsoft KB933666 - Security Update for Excel 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=9567C583-556F -4379-80BA-3E0C8993C04C
References
Microsoft Excel Filter Records Remote Code Execution Vulnerability
References:
References:
- KB934233: MS07-023: Vulnerabilities in Microsoft Excel could allow remote code e (Microsoft)
- Microsoft Office Product Homepage (Microsoft)
- iDefense Security Advisory 05.08.07: Microsoft Excel Filter Record Code Executio (iDefense)
- ASA-2007-184 - MS07-023 Vulnerabilities in Microsoft Excel Could Allow Remote Co (Avaya)
- Microsoft Excel Filter Record Code Execution Vulnerability (iDefense Labs)
- Microsoft Security Bulletin MS07-023 (Microsoft)
- VU#253825 Microsoft Excel fails to properly process files with crafted filter re (US-CERT)