Microsoft Excel Index Array Remote Code Execution Vulnerability
BID:30639
Info
Microsoft Excel Index Array Remote Code Execution Vulnerability
| Bugtraq ID: | 30639 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-3005 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2008 12:00AM |
| Updated: | Aug 25 2008 09:05PM |
| Credit: | VeriSign iDefense VCP |
| Vulnerable: |
Microsoft Office 2008 for Mac 0 Microsoft Office 2004 for Mac 0 Microsoft Office 2000 SP3 Microsoft Excel 2002 SP3 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Excel Index Array Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file.
Successful exploits may allow an attacker to execute arbitrary code with the privileges of the user running the application.
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file.
Successful exploits may allow an attacker to execute arbitrary code with the privileges of the user running the application.
Exploit / POC
Microsoft Excel Index Array Remote Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Excel Index Array Remote Code Execution Vulnerability
Solution:
Microsoft has released a security bulletin that addresses this vulnerability.
Microsoft Office 2008 for Mac 0
Microsoft Excel 2002 SP3
Microsoft Office 2004 for Mac 0
Microsoft Office 2000 SP3
Solution:
Microsoft has released a security bulletin that addresses this vulnerability.
Microsoft Office 2008 for Mac 0
-
Microsoft Microsoft Office 2008 for Mac 12.1.2 Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=9515C70D-BE80 -4ADE-856A-EA542F7D84E1
Microsoft Excel 2002 SP3
-
Microsoft Security Update for Microsoft Excel 2002 (KB951551)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9BBF7550-F5C4 -4B9B-BD86-1E7BE6C42EB5
Microsoft Office 2004 for Mac 0
-
Microsoft Microsoft Office 2004 for Mac 11.5.1 Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=EBD3AF0C-3F62 -4D18-BF45-881655683BD5&displaylang=en
Microsoft Office 2000 SP3
-
Microsoft Security Update for Microsoft Excel 2000 (KB951582)
http://www.microsoft.com/downloads/details.aspx?FamilyId=4bf8688e-e5b9 -4e53-a1a1-8cf1acfdb80b
References
Microsoft Excel Index Array Remote Code Execution Vulnerability
References:
References: