Lucene search

K
cveMicrosoftCVE-2009-3133
HistoryNov 11, 2009 - 8:30 p.m.

CVE-2009-3133

2009-11-1120:30:00
CWE-94
microsoft
web.nvd.nist.gov
41
microsoft
office
excel
vulnerability
remote code execution
memory corruption
nvd
cve-2009-3133

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.32

Percentile

97.0%

Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to โ€œloading Excel records,โ€ aka โ€œExcel Document Parsing Memory Corruption Vulnerability.โ€

Affected configurations

Nvd
Node
microsoftcompatibility_pack_word_excel_powerpointMatch2007sp1
OR
microsoftcompatibility_pack_word_excel_powerpointMatch2007sp2
OR
microsoftexcelMatch2002sp3
OR
microsoftexcelMatch2003sp3
OR
microsoftexcelMatch2007sp1
OR
microsoftexcelMatch2007sp2
OR
microsoftexcel_viewersp1
OR
microsoftexcel_viewersp2
OR
microsoftexcel_viewerMatch2003sp3
OR
microsoftofficeMatch2004mac
OR
microsoftofficeMatch2008mac
OR
microsoftopen_xml_file_format_convertermac
VendorProductVersionCPE
microsoftcompatibility_pack_word_excel_powerpoint2007cpe:2.3:a:microsoft:compatibility_pack_word_excel_powerpoint:2007:sp1:*:*:*:*:*:*
microsoftcompatibility_pack_word_excel_powerpoint2007cpe:2.3:a:microsoft:compatibility_pack_word_excel_powerpoint:2007:sp2:*:*:*:*:*:*
microsoftexcel2002cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*
microsoftexcel2003cpe:2.3:a:microsoft:excel:2003:sp3:*:*:*:*:*:*
microsoftexcel2007cpe:2.3:a:microsoft:excel:2007:sp1:*:*:*:*:*:*
microsoftexcel2007cpe:2.3:a:microsoft:excel:2007:sp2:*:*:*:*:*:*
microsoftexcel_viewer*cpe:2.3:a:microsoft:excel_viewer:*:sp1:*:*:*:*:*:*
microsoftexcel_viewer*cpe:2.3:a:microsoft:excel_viewer:*:sp2:*:*:*:*:*:*
microsoftexcel_viewer2003cpe:2.3:a:microsoft:excel_viewer:2003:sp3:*:*:*:*:*:*
microsoftoffice2004cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.32

Percentile

97.0%