imPC@ndo IT

Tracker / CVE-2010-0262

CVE-2010-0262

High 9.3

Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."

Affected products and versions

microsoft excel
microsoft office
microsoft office_compatibility_pack
microsoft office_excel_viewer
microsoft office_sharepoint_server
microsoft open_xml_file_format_converter

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References