Lucene search

K
cve[email protected]CVE-2007-1756
HistoryJul 10, 2007 - 10:30 p.m.

CVE-2007-1756

2007-07-1022:30:00
web.nvd.nist.gov
27
excel
validation
arbitrary code execution
user-assisted
remote attackers
cve-2007-1756
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.755 High

EPSS

Percentile

98.2%

Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka โ€œCalculation Error Vulnerabilityโ€.

Affected configurations

NVD
Node
microsoftexcelMatch2000sp3
OR
microsoftexcelMatch2002sp3
OR
microsoftexcelMatch2003sp2
OR
microsoftexcelMatch2007
OR
microsoftexcel_viewerMatch2003
OR
microsoftofficeMatch2000sp3
OR
microsoftofficeMatch2003
OR
microsoftofficeMatch2003sp2
OR
microsoftofficeMatch2007
OR
microsoftofficeMatchxpsp3

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.755 High

EPSS

Percentile

98.2%