Microsoft Excel Real Time Data (RTD) Remote Code Execution Vulnerability
BID:40524
Info
Microsoft Excel Real Time Data (RTD) Remote Code Execution Vulnerability
| Bugtraq ID: | 40524 |
| Class: | Unknown |
| CVE: |
CVE-2010-1246 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2010 12:00AM |
| Updated: | Sep 10 2010 11:32AM |
| Credit: | Nicolas Joly of VUPEN Vulnerability Research Team |
| Vulnerable: |
Microsoft Excel 2002 SP3 Microsoft Excel 2002 SP2 Microsoft Excel 2002 SP1 Microsoft Excel 2002 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Excel Real Time Data (RTD) Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Excel ('.xls') file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application.
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Excel ('.xls') file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application.
Exploit / POC
Microsoft Excel Real Time Data (RTD) Remote Code Execution Vulnerability
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Microsoft Excel Real Time Data (RTD) Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Excel 2002 SP3
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Excel 2002 SP3
-
Microsoft Security Update for Microsoft Excel 2002 (KB982299)
http://www.microsoft.com/downloads/details.aspx?familyid=fec14a92-79a1 -4281-8ee2-659b2dfd283f
References
Microsoft Excel Real Time Data (RTD) Remote Code Execution Vulnerability
References:
References:
- Microsoft Excel Homepage (Microsoft )
- MOAUB #10 �?? Excel RTD Memory Corruption (Abysssec Research)
- VUPEN Security Research - Microsoft Office Excel RTD Stack Overflow Vulnerabilit ("VUPEN Security Research"
) - ASA-2010-161 MS10-038 Vulnerabilities in Microsoft Office Excel Could Allow Remo (Avaya)
- Microsoft Security Bulletin MS10-038 (Microsoft)