Lucene search

K
cve[email protected]CVE-2007-0028
HistoryJan 09, 2007 - 11:28 p.m.

CVE-2007-0028

2007-01-0923:28:00
CWE-20
web.nvd.nist.gov
27
microsoft
excel
cve-2007-0028
remote execution
vulnerability
security
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.767 High

EPSS

Percentile

98.2%

Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an “Improper Memory Access Vulnerability.” NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.

Affected configurations

NVD
Node
microsoftexcelMatch2000
OR
microsoftofficeMatch2000sp3
Node
microsoftexcelMatch2002
OR
microsoftofficeMatchxpsp3
Node
microsoftexcelMatch2003
OR
microsoftofficeMatch2003sp2
Node
microsoftexcel_viewerMatch2003
OR
microsoftworksMatch2004
OR
microsoftworksMatch2005
Node
microsoftofficeMatch2004mac
OR
microsoftofficeMatchv.xmac

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.767 High

EPSS

Percentile

98.2%