Secunia Logo  


Secunia PSI WorldMap
 
Microsoft Excel Multiple Code Execution Vulnerabilities
Secunia Advisory: SA28506
Release Date: 2008-01-16
Last Update: 2008-03-14
Popularity: 36,286 views

Critical:
Extremely critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software:Microsoft Excel 2000
Microsoft Excel 2002
Microsoft Excel 2003
Microsoft Office 2000
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2004 for Mac
Microsoft Office 2007
Microsoft Office 2008 for Mac
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Excel 2007
Microsoft Office Excel Viewer 2003

Binary Analysis: BA356 :: Available for 1 Credit
BA422 :: Available for 1 Credit
BA428 :: Available for 1 Credit
BA433 :: Available for 1 Credit

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Apply patches.

Excel 2000 SP3:
http://www.microsoft.com/downloads/de...=f7f90c30-1bfd-406b-a77f-612443e30185

Excel 2002 SP3:
http://www.microsoft.com/downloads/de...=907f96d5-d1e9-4471-b41c-3ac811e63038

Excel 2003 SP2:
http://www.microsoft.com/downloads/de...=296e5f2c-f594-41c8-a20a-3e4c40ae3948

Excel 2007:
http://www.microsoft.com/downloads/de...=e7634cb5-9531-4284-9554-4168fc488e0c

Microsoft Office Excel Viewer 2003:
http://www.microsoft.com/downloads/de...=280bb2ac-b21a-46b5-8751-5a50fbebf107

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats:
http://www.microsoft.com/downloads/de...=e9251d71-9098-4125-ae91-7d4c83ea58ad

Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/de...=95DCEB37-B35F-46DB-B280-DB0F3B298AA9

Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/de...=8FE8C32A-6D7A-482B-97C6-42562F089EE4

Provided and/or discovered by:
1) Discovered as a 0-day. The vendor also credits Matt Richard, VeriSign.
2) Greg MacManus, iDefense Labs.
3) The vendor credits Yoshiya Sasaki, JFE Systems.
4) The vendor credits Bing Liu, Fortinet.
5) Reported by an anonymous person via iDefense Labs.
6) Cody Pierce, TippingPoint DVLabs.
7) The vendor credits Moti Joseph and Dan Hubbard, Websense Security Labs.

Changelog:
2008-03-11: Updated "Solution" section. Added additional vulnerabilities.
2008-03-12: Added additional information provided by iDefense Labs and TippingPoint.
2008-03-14: Added links in "Other References" section describing an issue regarding Microsoft Excel 2003 calculations. Updated "Extended Solution" section.

Original Advisory:
MS08-014 (KB949029):
http://www.microsoft.com/technet/security/Bulletin/MS08-014.mspx

Microsoft (KB947563):
http://www.microsoft.com/technet/security/advisory/947563.mspx

iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=671
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=672

TippingPoint DVLabs:
http://dvlabs.tippingpoint.com/advisory/TPTI-08-03

Other References:
MSRC Blog:
http://blogs.technet.com/msrc/archive...pdate-march-2008-monthly-release.aspx

KB950340:
http://support.microsoft.com/kb/950340

Extended Solution:
The "Extended Solution" section is available for Secunia customers only. Request a trial and get access to the Secunia Customer Area and Extended Secunia advisories.

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Internet Explorer PDF Export Information Disclosure // 72 views
2. Internet Explorer Layout Handling Memory Corruption Vulnerability // 53 views
3. Gentoo update for uw-imap and c-client // 53 views
4. ISC BIND DNSSEC Cache Poisoning Vulnerability // 51 views
5. Firefox Yoono Extension Cross-Context Scripting Vulnerability // 44 views
6. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 41 views
7. Sun Solaris sshd Timeout Mechanism Denial of Service // 41 views
8. Symantec Altiris ConsoleUtilities ActiveX Control "RunCmd()" Buffer Overflow // 38 views
9. Quick.CMS "admin.php" Cross-Site Request Forgery Vulnerability // 38 views
10. Adobe Flash Player Multiple Vulnerabilities // 36 views