Microsoft Excel Invalid Object Remote Code Execution Vulnerability
BID:33870
Info
Microsoft Excel Invalid Object Remote Code Execution Vulnerability
| Bugtraq ID: | 33870 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0238 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2009 12:00AM |
| Updated: | May 01 2009 12:36AM |
| Credit: | Symantec |
| Vulnerable: |
Microsoft Open XML File Format Converter for Mac 0 Microsoft Excel 2008 for Mac 0 Microsoft Excel 2007 SP1 Microsoft Excel 2007 0 Microsoft Excel 2007 0 Microsoft Excel 2004 for Mac 0 Microsoft Excel 2003 SP3 Microsoft Excel 2003 SP2 Microsoft Excel 2003 SP1 Microsoft Excel 2003 Microsoft Excel 2002 SP3 Microsoft Excel 2002 SP2 Microsoft Excel 2002 SP1 Microsoft Excel 2002 Microsoft Excel 2000 SR1 Microsoft Excel 2000 SP3 Microsoft Excel 2000 SP2 Microsoft Excel 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Excel Invalid Object Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file.
Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will result in a denial-of-service condition.
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted Excel file.
Successful exploits may allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Excel Invalid Object Remote Code Execution Vulnerability
Symantec has detected active in-the-wild exploit attempts. This issue is detected as 'Trojan.Mdropper.AC'.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Symantec has detected active in-the-wild exploit attempts. This issue is detected as 'Trojan.Mdropper.AC'.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Excel Invalid Object Remote Code Execution Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Microsoft Excel 2003 SP3
Microsoft Excel 2007 SP1
Microsoft Excel 2002 SP3
Microsoft Excel 2000 SP3
Solution:
The vendor has released an update. Please see the references for more information.
Microsoft Excel 2003 SP3
-
Microsoft Security Update for Microsoft Office Excel 2003 (KB959995)
http://www.microsoft.com/downloads/details.aspx?familyid=d9dbfa63-c0cb -4c84-9b8a-6e52568045b0
Microsoft Excel 2007 SP1
-
Microsoft Security Update for Microsoft Office Excel 2007 (KB959997)
http://www.microsoft.com/downloads/details.aspx?familyid=50d8630b-1365 -4007-81a0-18c0d6d4b86e
Microsoft Excel 2002 SP3
-
Microsoft Security Update for Microsoft Excel 2002 (KB959988)
http://www.microsoft.com/downloads/details.aspx?familyid=9a52bf4b-05f6 -4b73-94b9-28ed7e20f86c
Microsoft Excel 2000 SP3
-
Microsoft Security Update for Microsoft Excel 2000 (KB959964)
http://www.microsoft.com/downloads/details.aspx?familyid=3dc8b670-25a5 -4f46-b7de-12bc693b628a
References
Microsoft Excel Invalid Object Remote Code Execution Vulnerability
References:
References:
- Microsoft Excel Homepage (Microsoft )
- More information about the new Excel vulnerability (Microsoft)
- Microsoft Security Advisory 968272 (Microsoft)
- Microsoft Security Bulletin MS09-009 (Microsoft)