Microsoft Excel WOPT Record Parsing Heap Memory Corruption Remote Code Execution Vulnerability
BID:40522
Info
Microsoft Excel WOPT Record Parsing Heap Memory Corruption Remote Code Execution Vulnerability
| Bugtraq ID: | 40522 |
| Class: | Unknown |
| CVE: |
CVE-2010-0824 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2010 12:00AM |
| Updated: | Sep 21 2010 12:32PM |
| Credit: | Nicolas Joly of VUPEN Vulnerability Research Team |
| Vulnerable: |
Microsoft Office 2004 for Mac 0 Microsoft Excel 2002 SP3 Microsoft Excel 2002 SP2 Microsoft Excel 2002 SP1 Microsoft Excel 2002 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Excel WOPT Record Parsing Heap Memory Corruption Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Excel ('.xls') file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application.
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Excel ('.xls') file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application.
Exploit / POC
Microsoft Excel WOPT Record Parsing Heap Memory Corruption Remote Code Execution Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Microsoft Excel WOPT Record Parsing Heap Memory Corruption Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Excel 2002 SP3
Microsoft Office 2004 for Mac 0
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Excel 2002 SP3
-
Microsoft Security Update for Microsoft Excel 2002 (KB982299)
http://www.microsoft.com/downloads/details.aspx?familyid=fec14a92-79a1 -4281-8ee2-659b2dfd283f
Microsoft Office 2004 for Mac 0
-
Microsoft Microsoft Office 2004 for Mac 11.5.9 Update
http://www.microsoft.com/downloads/details.aspx?FamilyID=16c71ab8-9284 -407a-856a-93c67995f125
References
Microsoft Excel WOPT Record Parsing Heap Memory Corruption Remote Code Execution Vulnerability
References:
References:
- Microsoft Excel Homepage (Microsoft )
- VUPEN Security Research - Microsoft Office Excel WOPT Heap Corruption Vulnerabil ("VUPEN Security Research"
) - ASA-2010-161 MS10-038 Vulnerabilities in Microsoft Office Excel Could Allow Remo (Avaya)
- Microsoft Security Bulletin MS10-038 (Microsoft)