Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4265

Опубликовано: 10 дек. 2008
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing Vulnerability."

Комментарий

http://www.microsoft.com/technet/security/Bulletin/MS08-074.mspx

File Format Parsing Vulnerability - CVE-2008-4265

A remote code execution vulnerability exists in Microsoft Office Excel as a result of memory corruption when loading Excel records. The vulnerability could allow remote code execution if a user opens a specially crafted Excel file that includes a malformed object. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:microsoft:office_excel:2000:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_excel:2002:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_excel:2003:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_excel:2007:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_excel:2007:sp1:*:*:*:*:*:*

Одно из

cpe:2.3:a:microsoft:20007_office_system:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:20007_office_system:sp1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*
cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*
cpe:2.3:a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007:*:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_excel_viewer:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_excel_viewer:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_excel_viewer:2003:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:open_xml_file_format_converter:*:*:mac:*:*:*:*:*

EPSS

Процентиль: 98%
0.6248
Средний

9.3 Critical

CVSS2

Дефекты

CWE-399

Связанные уязвимости

github
почти 4 года назад

Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing Vulnerability."

EPSS

Процентиль: 98%
0.6248
Средний

9.3 Critical

CVSS2

Дефекты

CWE-399