imPC@ndo IT

Tracker / CVE-2010-0260

CVE-2010-0260

High 9.3

Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXTUPLE record is broken up into several records," aka "Microsoft Office Excel MDXTUPLE Record Heap Overflow Vulnerability."

Affected products and versions

microsoft excel
microsoft office
microsoft office_compatibility_pack
microsoft office_excel_viewer
microsoft office_sharepoint_server
microsoft open_xml_file_format_converter

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References