Lucene search

K
cve[email protected]CVE-2012-0184
HistoryMay 09, 2012 - 12:55 a.m.

CVE-2012-0184

2012-05-0900:55:01
CWE-264
web.nvd.nist.gov
118
cve-2012-0184
microsoft excel
memory corruption
remote code execution
vulnerability
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.892 High

EPSS

Percentile

98.8%

Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka โ€œExcel SXLI Record Memory Corruption Vulnerability.โ€

Affected configurations

NVD
Node
microsoftexcelMatch2003sp3
OR
microsoftexcelMatch2007sp2
OR
microsoftexcelMatch2007sp3
OR
microsoftexcelMatch2010
OR
microsoftexcelMatch2010sp1
OR
microsoftexcel_viewer
OR
microsoftofficeMatch2008
OR
microsoftofficeMatch2011mac
OR
microsoftoffice_compatibility_packsp2
OR
microsoftoffice_compatibility_packsp3

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.892 High

EPSS

Percentile

98.8%