Lucene search

K
cve[email protected]CVE-2008-4266
HistoryDec 10, 2008 - 2:00 p.m.

CVE-2008-4266

2008-12-1014:00:01
CWE-399
web.nvd.nist.gov
34
cve-2008-4266
excel
microsoft office
vulnerability
remote code execution
nvd
stack corruption

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.267 Low

EPSS

Percentile

96.8%

Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3; Excel Viewer 2003 Gold and SP3; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Excel spreadsheet with a NAME record that contains an invalid index value, which triggers stack corruption, aka β€œExcel Global Array Memory Corruption Vulnerability.”

Affected configurations

NVD
Node
microsoftexcelMatch2000sp3
OR
microsoftexcelMatch2002sp3
OR
microsoftexcelMatch2003sp3
OR
microsoftexcel_viewerMatch2003
OR
microsoftexcel_viewerMatch2003sp3
OR
microsoftofficeMatch2004mac
OR
microsoftofficeMatch2008mac
OR
microsoftopen_xml_file_format_convertermac

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.267 Low

EPSS

Percentile

96.8%