|
|
|
|
| |
Credit:
The information has been provided by Chaouki Bekrar.
The original article can be found at: http://osdir.com/ml/bugtraq.security/2010-10/msg00106.html
|
| |
Vulnerable Systems:
* Microsoft Office 2007 Service Pack 2
* Microsoft Office XP Service Pack 3
* Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2
* Microsoft Excel Viewer Service Pack 2
The vulnerability is caused by an array indexing error when processing RealTimeData records in an Excel file, which could be exploited by remote attackers to execute arbitrary code by tricking a user into opening a specially crafted Excel document.
Patch Availability:
Apply MS10-080 security update:
http://www.microsoft.com/technet/security/bulletin/ms10-080.mspx
CVE Information:
CVE-2010-3240
Disclosure Timeline:
2010-04-02 - Vendor notified
2010-04-02 - Vendor response
2010-08-25 - Status update received
2010-10-12 - Coordinated public Disclosure
|
|
|
|
|