CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
High
EPSS
Percentile
98.2%
Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which “a MDXSET record is broken up into several records,” aka “Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability.”
Vendor | Product | Version | CPE |
---|---|---|---|
microsoft | excel | 2002 | cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:* |
microsoft | excel | 2003 | cpe:2.3:a:microsoft:excel:2003:sp3:*:*:*:*:*:* |
microsoft | excel | 2007 | cpe:2.3:a:microsoft:excel:2007:sp1:*:*:*:*:*:* |
microsoft | excel | 2007 | cpe:2.3:a:microsoft:excel:2007:sp2:*:*:*:*:*:* |
microsoft | office | 2004 | cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:* |
microsoft | office | 2008 | cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:* |
microsoft | office_compatibility_pack | 2007 | cpe:2.3:a:microsoft:office_compatibility_pack:2007:sp1:*:*:*:*:*:* |
microsoft | office_compatibility_pack | 2007 | cpe:2.3:a:microsoft:office_compatibility_pack:2007:sp2:*:*:*:*:*:* |
microsoft | office_excel_viewer | * | cpe:2.3:a:microsoft:office_excel_viewer:*:sp1:*:*:*:*:*:* |
microsoft | office_excel_viewer | * | cpe:2.3:a:microsoft:office_excel_viewer:*:sp2:*:*:*:*:*:* |
labs.idefense.com/intelligence/vulnerabilities/display.php?id=861
www.securitytracker.com/id?1023698
www.us-cert.gov/cas/techalerts/TA10-068A.html
docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-017
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8479