Lucene search

K
zdiArnaud Dovi aka 'class101', http://heapoverflow.comZDI-06-004
HistoryMar 14, 2006 - 12:00 a.m.

Microsoft Excel File Format Parsing Vulnerability

2006-03-1400:00:00
Arnaud Dovi aka 'class101', http://heapoverflow.com
www.zerodayinitiative.com
14

0.956 High

EPSS

Percentile

99.4%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file. The specific flaw exists within the parsing of the BIFF file format used by Microsoft Excel. During the processing of malformed BOOLERR records, user-supplied data may be insecurely referenced thereby leading to the eventual execution of arbitrary code.

0.956 High

EPSS

Percentile

99.4%