Lucene search

K
seebugRootSSV:20932
HistorySep 15, 2011 - 12:00 a.m.

Microsoft Excel畸形记录远程代码执行漏洞(MS11-072)

2011-09-1500:00:00
Root
www.seebug.org
23

EPSS

0.952

Percentile

99.4%

BUGTRAQ ID: 49478
CVE(CAN) ID: CVE-2011-1988

Microsoft Excel是由Microsoft为Windows和Apple Macintosh操作系统的电脑而编写和运行的一款试算表软件。

Microsoft Excel在处理畸形记录时存在远程代码执行漏洞,远程攻击者可利用此漏洞以当前用户权限执行任意代码。

Excel解析电子表格文件中的特制记录时,其中的特定值可触发内存破坏漏洞。

Microsoft Excel 2010
Microsoft Excel 2007
Microsoft Excel 2003
Microsoft Office Compatibility Pack 2007 SP2
Microsoft Office Compatibility Pack 2007 SP1
Microsoft Office Compatibility Pack 2007 0
Microsoft Office 2011 for Mac SP1
Microsoft Office 2011 for Mac 0
Microsoft Office 2008 for Mac 0
Microsoft Office 2004 for Mac 0
Microsoft Open XML File Format Converter for Mac
厂商补丁:

Microsoft

Microsoft已经为此发布了一个安全公告(MS11-073)以及相应补丁:

MS11-073:Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505)

链接:http://www.microsoft.com/technet/security/bulletin/MS11-072.mspx