imPC@ndo IT

Tracker / CVE-2009-1134

CVE-2009-1134

High 9.3

Excel in 2007 Microsoft Office System SP1 and SP2; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a BIFF file with a malformed Qsir (0x806) record object, aka "Record Pointer Corruption Vulnerability."

Affected products and versions

microsoft office
microsoft office_compatibility_pack_for_word_excel_ppt_2007
microsoft office_excel
microsoft office_excel_viewer
microsoft office_sharepoint_server
microsoft open_xml_file_format_converter

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References