J-Security Center

Title: Microsoft Excel Index Parsing Remote Code Execution Vulnerability

Severity: HIGH

Description:

Microsoft Excel is a spreadsheet application that is part of the Microsoft Office suite.

Excel is prone to a remote code-execution vulnerability when parsing an index value while loading a specially crafted formula in a malformed Excel ('.xls') file. The issue results in pointer corruption.

Attackers can exploit this issue by enticing victims into opening a malicious Excel file.

Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application.

Affected Products:

  • Microsoft Excel 2002
  • Microsoft Excel 2002 SP1
  • Microsoft Excel 2002 SP2
  • Microsoft Excel 2002 SP3
  • Microsoft Excel 2003
  • Microsoft Excel 2003 SP1
  • Microsoft Excel 2003 SP2
  • Microsoft Excel 2003 SP3
  • Microsoft Excel 2007
  • Microsoft Excel 2007
  • Microsoft Excel 2007 SP1
  • Microsoft Excel 2007 SP2
  • Microsoft Excel Compatibility Pack
  • Microsoft Excel Viewer 2003
  • Microsoft Excel Viewer 2003 SP3
  • Microsoft Office 2003
  • Microsoft Office 2003 SP1
  • Microsoft Office 2004 for Mac
  • Microsoft Office 2008 for Mac
  • Microsoft Office Compatibility Pack 2007 SP1
  • Microsoft Office Compatibility Pack 2007 SP2
  • Microsoft Office Excel Viewer 2003
  • Microsoft Office Excel Viewer 2003 SP3
  • Microsoft Office Excel Viewer SP1
  • Microsoft Office Excel Viewer SP2
  • Microsoft Office XP
  • Microsoft Office XP SP1
  • Microsoft Office XP SP2
  • Microsoft Office XP SP3
  • Microsoft Open XML File Format Converter for Mac

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.