Lucene search

K
cveMicrosoftCVE-2012-0185
HistoryMay 09, 2012 - 12:55 a.m.

CVE-2012-0185

2012-05-0900:55:01
CWE-264
microsoft
web.nvd.nist.gov
53
cve-2012-0185
excel
2007
2010
viewer
compatibility pack
heap overflow
vulnerability
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.952

Percentile

99.4%

Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka “Excel MergeCells Record Heap Overflow Vulnerability.”

Affected configurations

Nvd
Node
microsoftexcelMatch2007sp2
OR
microsoftexcelMatch2007sp3
OR
microsoftexcelMatch2010
OR
microsoftexcelMatch2010sp1
OR
microsoftexcel_viewer
OR
microsoftoffice_compatibility_packsp2
OR
microsoftoffice_compatibility_packsp3
VendorProductVersionCPE
microsoftexcel2007cpe:2.3:a:microsoft:excel:2007:sp2:*:*:*:*:*:*
microsoftexcel2007cpe:2.3:a:microsoft:excel:2007:sp3:*:*:*:*:*:*
microsoftexcel2010cpe:2.3:a:microsoft:excel:2010:*:*:*:*:*:*:*
microsoftexcel2010cpe:2.3:a:microsoft:excel:2010:sp1:*:*:*:*:*:*
microsoftexcel_viewer*cpe:2.3:a:microsoft:excel_viewer:*:*:*:*:*:*:*:*
microsoftoffice_compatibility_pack*cpe:2.3:a:microsoft:office_compatibility_pack:*:sp2:*:*:*:*:*:*
microsoftoffice_compatibility_pack*cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.952

Percentile

99.4%