Vulnerability Note VU#613740
Microsoft Excel memory access vulnerability
Overview
An unspecified vulnerability in Microsoft Excel may allow a remote attacker to execute arbitrary code.
Description
Microsoft Excel contains a vulnerability. According to Microsoft Security Bulletin MS07-015 The vulnerability is caused when Excel opens a specially crafted Excel file which will results in the access of memory outside intended regions when parsing placeholder data. This vulnerability affects Microsoft Excel for both Microsoft Windows and Mac OS X. |
Impact
By convincing a user to open a specially crafted Office document, an attacker could execute arbitrary code. |
Solution
Apply Update for Microsoft |
Do not open untrusted Office documents |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Affected | - | 13 Feb 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.microsoft.com/technet/security/advisory/932553.mspx
- http://www.microsoft.com/technet/security/Bulletin/MS07-015.mspx
- http://www.symantec.com/enterprise/security_response/weblog/2007/02/latest_office_zeroday_vulnerab.html
- http://secunia.com/advisories/24008/
- http://securitytracker.com/alerts/2007/Feb/1017584.html
- http://www.securityfocus.com/bid/22383
Credit
This vulnerability was reported in Microsoft Security Advisory (932553).
This document was written by Jeff Gennari based on information from Microsoft.
Other Information
- CVE IDs: CVE-2007-0671
- Date Public: 02 Feb 2007
- Date First Published: 05 Feb 2007
- Date Last Updated: 13 Mar 2007
- Severity Metric: 24.98
- Document Revision: 18
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.