imPC@ndo IT

Tracker / CVE-2009-3128

CVE-2009-3128

High 9.3

Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."

Affected products and versions

microsoft compatibility_pack_word_excel_powerpoint
microsoft excel
microsoft excel_viewer
microsoft office
microsoft open_xml_file_format_converter

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References