[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-0979Date: (C)2011-02-10   (M)2023-12-22


Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a malformed object record, related to a "stray reference," aka "Excel Linked List Corruption Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1025337
SECUNIA-39122
SECUNIA-43231
OSVDB-70904
ADV-2011-0940
MS11-021
TA11-102A
http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsoft
http://zerodayinitiative.com/advisories/ZDI-11-041/
oval:org.mitre.oval:def:12595

CPE    11
cpe:/a:microsoft:office:2011::mac
cpe:/a:microsoft:excel:2003:sp3
cpe:/a:microsoft:open_xml_file_format_converter:::mac
cpe:/a:microsoft:office:2008::mac
...
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:211
oval:org.secpod.oval:def:822

© SecPod Technologies