Lucene search

K
cve[email protected]CVE-2008-3471
HistoryOct 15, 2008 - 12:12 a.m.

CVE-2008-3471

2008-10-1500:12:15
CWE-787
web.nvd.nist.gov
30
cve-2008-3471
microsoft excel
stack-based buffer overflow
remote code execution
file format parsing vulnerability
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.932 High

EPSS

Percentile

99.1%

Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a BIFF file with a malformed record that triggers a user-influenced size calculation, aka β€œFile Format Parsing Vulnerability.”

Affected configurations

NVD
Node
microsoftexcelMatch2003sp2
OR
microsoftexcelMatch2003sp3
OR
microsoftexcelMatch2007-
OR
microsoftexcelMatch2007sp1
OR
microsoftexcel_viewerMatch-
OR
microsoftexcel_viewerMatch2003-
OR
microsoftexcel_viewerMatch2003sp3
OR
microsoftofficeMatch2004macos
OR
microsoftofficeMatch2008macos
OR
microsoftoffice_compatibility_packMatch2007-
OR
microsoftoffice_compatibility_packMatch2007sp1
OR
microsoftopen_xml_file_format_converterMatch-macos

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.932 High

EPSS

Percentile

99.1%