Microsoft Excel HFPicture Record Parsing Remote Code Execution Vulnerability
BID:40526
Info
Microsoft Excel HFPicture Record Parsing Remote Code Execution Vulnerability
| Bugtraq ID: | 40526 |
| Class: | Unknown |
| CVE: |
CVE-2010-1248 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2010 12:00AM |
| Updated: | May 30 2011 04:41PM |
| Credit: | Nicolas Joly of VUPEN Vulnerability Research Team |
| Vulnerable: |
Microsoft Office 2004 for Mac 0 Microsoft Excel 2002 SP3 Microsoft Excel 2002 SP2 Microsoft Excel 2002 SP1 Microsoft Excel 2002 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Excel HFPicture Record Parsing Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Excel ('.xls') file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application.
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Excel ('.xls') file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application.
Exploit / POC
Microsoft Excel HFPicture Record Parsing Remote Code Execution Vulnerability
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof-of-concept is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept is available:
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof-of-concept is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept is available:
Solution / Fix
Microsoft Excel HFPicture Record Parsing Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Excel 2002 SP3
Microsoft Office 2004 for Mac 0
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Excel 2002 SP3
-
Microsoft Security Update for Microsoft Excel 2002 (KB982299)
http://www.microsoft.com/downloads/details.aspx?familyid=fec14a92-79a1 -4281-8ee2-659b2dfd283f
Microsoft Office 2004 for Mac 0
-
Microsoft Microsoft Office 2004 for Mac 11.5.9 Update
http://www.microsoft.com/downloads/details.aspx?FamilyID=16c71ab8-9284 -407a-856a-93c67995f125
References
Microsoft Excel HFPicture Record Parsing Remote Code Execution Vulnerability
References:
References:
- MAOUB #16 �?? Microsoft Excel HFPicture Record Parsing Remote Code Execution Vulne (Abysssec)
- Microsoft Excel Homepage (Microsoft )
- VUPEN Security Research - Microsoft Office Excel HFPicture Buffer Overflow Vulne ("VUPEN Security Research"
) - ASA-2010-161 MS10-038 Vulnerabilities in Microsoft Office Excel Could Allow Remo (Avaya)
- Microsoft Security Bulletin MS10-038 (Microsoft)