[Forgot Password]
Login  Register Subscribe

23631

 
 

126998

 
 

102010

 
 

909

 
 

80911

 
 

121

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2011-0979Date: (C)2011-02-10   (M)2018-02-19


Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a malformed object record, related to a "stray reference," aka "Excel Linked List Corruption Vulnerability."

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score  : CVSS Score  : 9.3
Exploit Score: Exploit Score: 8.6
Impact Score : Impact Score : 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector: NETWORK
Attack Complexity: Access Complexity: MEDIUM
Privileges Required: Authentication: NONE
User Interaction: Confidentiality: COMPLETE
Scope: Integrity: COMPLETE
Confidentiality: Availability: COMPLETE
Integrity:  
Availability:  
  





Reference:
SECTRACK-1025337
SECUNIA-39122
SECUNIA-43231
OSVDB-70904
ADV-2011-0940
MS11-021
TA11-102A
http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsoft
http://zerodayinitiative.com/advisories/ZDI-11-041/

CPE    11
cpe:/a:microsoft:open_xml_file_format_converter:::mac
cpe:/a:microsoft:office:2004::mac
cpe:/a:microsoft:office_compatibility_pack:2007:sp2
cpe:/a:microsoft:excel:-:-:x64
...
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:211
oval:org.secpod.oval:def:822

© 2013 SecPod Technologies