Microsoft Excel Worksheet Index Value Remote Code Execution Vulnerability
BID:25280
Info
Microsoft Excel Worksheet Index Value Remote Code Execution Vulnerability
| Bugtraq ID: | 25280 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3890 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2007 12:00AM |
| Updated: | Sep 04 2007 09:11PM |
| Credit: | Dyon Balding of Secunia Research is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Office 2004 for Mac 0 Microsoft Excel Viewer 2003 0 Microsoft Excel 2003 SP2 Microsoft Excel 2003 SP1 Microsoft Excel 2003 Microsoft Excel 2002 SP3 Microsoft Excel 2002 SP2 Microsoft Excel 2002 SP1 Microsoft Excel 2002 Microsoft Excel 2000 SR1 Microsoft Excel 2000 SP3 Microsoft Excel 2000 SP2 Microsoft Excel 2000 0 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya CIE 1.0.2 Avaya CIE 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft Excel Worksheet Index Value Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file (.xls).
Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. This may facilitate a compromise of vulnerable computers.
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file (.xls).
Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. This may facilitate a compromise of vulnerable computers.
Exploit / POC
Microsoft Excel Worksheet Index Value Remote Code Execution Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Microsoft Excel Worksheet Index Value Remote Code Execution Vulnerability
Solution:
Microsoft released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Excel 2003 SP2
Microsoft Excel 2002 SP3
Microsoft Office 2004 for Mac 0
Microsoft Excel 2000 SP3
Microsoft Excel Viewer 2003 0
Solution:
Microsoft released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Excel 2003 SP2
-
Microsoft Security Update for Excel 2003 (KB940602)
http://www.microsoft.com/downloads/details.aspx?FamilyId=B0130E9E-8845 -4D79-AAA1-A21CC9388ABE&displaylang=en
Microsoft Excel 2002 SP3
-
Microsoft Security Update for Excel 2002 (KB940601)
http://www.microsoft.com/downloads/details.aspx?FamilyId=91308769-2577 -4F9F-8209-06F2C8C8A86F&displaylang=en
Microsoft Office 2004 for Mac 0
-
Microsoft Microsoft Office 2004 for Mac 11.3.7 Update
http://download.microsoft.com/download/E/9/B/E9B2A7C6-438A-4CF9-BB35-9 01C01F3C996/Office2004-1137UpdateEN.dmg
Microsoft Excel 2000 SP3
-
Microsoft Security Update for Excel 2000 (KB940596)
http://www.microsoft.com/downloads/details.aspx?FamilyId=082B98F7-9556 -4F1F-823A-C41DDF5A7C9A&displaylang=en
Microsoft Excel Viewer 2003 0
-
Microsoft Security Update for Excel Viewer 2003 (KB940604)
http://www.microsoft.com/downloads/details.aspx?FamilyId=C4A87572-3128 -44F7-8069-95535A78500A&displaylang=en
References
Microsoft Excel Worksheet Index Value Remote Code Execution Vulnerability
References:
References:
- Microsoft Excel Homepage (Microsoft )
- Technical Tips and Insights on MS07-049 and MS07-044 (Microsoft)
- ASA-2007-368 MS07-044 Vulnerability in Microsoft Excel Could Allow Remote Code E (Avaya)
- Microsoft Security Bulletin MS07-044 (Microsoft)