Microsoft Excel Indexing Validation Remote Code Execution Vulnerability
BID:30638
Info
Microsoft Excel Indexing Validation Remote Code Execution Vulnerability
| Bugtraq ID: | 30638 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-3004 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2008 12:00AM |
| Updated: | Aug 25 2008 09:05PM |
| Credit: | VeriSign iDefense VCP |
| Vulnerable: |
Microsoft Office 2008 for Mac 0 Microsoft Office 2004 for Mac 0 Microsoft Office 2000 SP3 Microsoft Excel Viewer 2003 0 Microsoft Excel 2003 SP3 Microsoft Excel 2003 SP2 Microsoft Excel 2002 SP3 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Excel Indexing Validation Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file.
Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. This may facilitate a compromise of vulnerable computers.
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file.
Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. This may facilitate a compromise of vulnerable computers.
Exploit / POC
Microsoft Excel Indexing Validation Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Excel Indexing Validation Remote Code Execution Vulnerability
Solution:
Microsoft has released a security bulletin that addresses this vulnerability.
Microsoft Office 2008 for Mac 0
Microsoft Excel 2002 SP3
Microsoft Excel 2003 SP2
Microsoft Office 2004 for Mac 0
Microsoft Excel 2003 SP3
Microsoft Office 2000 SP3
Microsoft Excel Viewer 2003 0
Solution:
Microsoft has released a security bulletin that addresses this vulnerability.
Microsoft Office 2008 for Mac 0
-
Microsoft Microsoft Office 2008 for Mac 12.1.2 Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=9515C70D-BE80 -4ADE-856A-EA542F7D84E1
Microsoft Excel 2002 SP3
-
Microsoft Security Update for Microsoft Excel 2002 (KB951551)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9BBF7550-F5C4 -4B9B-BD86-1E7BE6C42EB5
Microsoft Excel 2003 SP2
-
Microsoft Security Update for Microsoft Office Excel 2003 (KB951548)
http://www.microsoft.com/downloads/details.aspx?FamilyId=fc612e9a-bdf3 -4952-8ada-0de5a50973f0
Microsoft Office 2004 for Mac 0
-
Microsoft Microsoft Office 2004 for Mac 11.5.1 Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=EBD3AF0C-3F62 -4D18-BF45-881655683BD5
Microsoft Excel 2003 SP3
-
Microsoft Security Update for Microsoft Office Excel 2003 (KB951548)
http://www.microsoft.com/downloads/details.aspx?FamilyId=fc612e9a-bdf3 -4952-8ada-0de5a50973f0
Microsoft Office 2000 SP3
-
Microsoft Security Update for Microsoft Excel 2000 (KB951582)
http://www.microsoft.com/downloads/details.aspx?FamilyId=4bf8688e-e5b9 -4e53-a1a1-8cf1acfdb80b
Microsoft Excel Viewer 2003 0
-
Microsoft Security Update for Microsoft Office Excel Viewer 2003 (KB951589)
http://www.microsoft.com/downloads/details.aspx?FamilyId=d7ed9e75-15f2 -4950-98b3-93023ba0f4c1
References
Microsoft Excel Indexing Validation Remote Code Execution Vulnerability
References:
References: