Microsoft Excel SST Invalid Length Use After Free Remote Code Execution Vulnerability
BID:56430
Info
Microsoft Excel SST Invalid Length Use After Free Remote Code Execution Vulnerability
| Bugtraq ID: | 56430 |
| Class: | Unknown |
| CVE: |
CVE-2012-1887 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2012 12:00AM |
| Updated: | Apr 19 2013 02:40AM |
| Credit: | An anonymous researcher, working with the iDefense VCP |
| Vulnerable: |
Microsoft Office 2011 for Mac 0 Microsoft Office 2010 (64-bit edition) SP1 Microsoft Office 2010 (64-bit edition) 0 Microsoft Office 2010 (32-bit edition) 0 Microsoft Office 2010 (32-bit edition) SP1 Microsoft Office 2008 for Mac 0 Microsoft Office 2007 SP3 Microsoft Excel 2010 SP1 Microsoft Excel 2010 0 Microsoft Excel 2007 SP3 Microsoft Excel 2007 SP2 Microsoft Excel 2003 SP3 Microsoft Excel 2003 SP2 Microsoft Excel 2003 SP1 Microsoft Excel 2003 |
| Not Vulnerable: | |
Discussion
Microsoft Excel SST Invalid Length Use After Free Remote Code Execution Vulnerability
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Excel ('.xls') file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploits will result in denial-of-service conditions.
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to open a specially crafted Excel ('.xls') file.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploits will result in denial-of-service conditions.
Exploit / POC
Microsoft Excel SST Invalid Length Use After Free Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Excel SST Invalid Length Use After Free Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Solution:
The vendor has released an advisory and updates. Please see the references for details.
References
Microsoft Excel SST Invalid Length Use After Free Remote Code Execution Vulnerability
References:
References:
- Microsoft Excel Homepage (Microsoft )