Secunia Logo  


Secunia PSI WorldMap
 
Microsoft Excel Multiple Vulnerabilities
Secunia Advisory: SA35364
Release Date: 2009-06-09
Last Update: 2009-06-12
Popularity: 8,922 views

Critical:
Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software:Microsoft Excel 2000
Microsoft Excel 2002
Microsoft Excel 2003
Microsoft Office 2000
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2004 for Mac
Microsoft Office 2007
Microsoft Office 2008 for Mac
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Excel 2007
Microsoft Office Excel Viewer 2003
Microsoft Office Excel Viewer 2007
Microsoft Office SharePoint Server 2007
Microsoft Office XP
Microsoft Open XML File Format Converter for Mac

Binary Analysis: BA635 :: Available for 1 Credit
BA691 :: Available for 1 Credit
BA751 :: Available for 1 Credit
BA781 :: Available for 1 Credit

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Apply patches.

Microsoft Office Excel 2000 SP3:
http://www.microsoft.com/downloads/de...=dd16e243-b8e2-4afb-86b6-4d60214598eb

Microsoft Office Excel 2002 SP3:
http://www.microsoft.com/downloads/de...=dd80ce95-0aec-4493-b9d1-c3dad95c3415

Microsoft Office Excel 2003 SP3:
http://www.microsoft.com/downloads/de...=10156044-a5a4-4312-98a7-1b1ced625ddb

Microsoft Office Excel 2007 SP1:
http://www.microsoft.com/downloads/de...=2bcd565a-6acb-407d-80da-0398526ddf99

Microsoft Office Excel 2007 SP2:
http://www.microsoft.com/downloads/de...=2bcd565a-6acb-407d-80da-0398526ddf99

Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/de...=5557bfb7-ebb4-4c42-8042-41e830c4e550

Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/de...=58326da2-eb75-4b42-b1bc-e70319defb58

Open XML File Format Converter for Mac:
http://www.microsoft.com/downloads/de...=9d6d9eaa-8442-4184-8886-faab2803bde6

Microsoft Office Excel Viewer 2003 SP3:
http://www.microsoft.com/downloads/de...=20e6933d-85f8-4cec-9534-893789cd053e

Microsoft Office Excel Viewer:
http://www.microsoft.com/downloads/de...=ac0530dc-7f63-4ad0-85c1-784ad28156cf

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1:
http://www.microsoft.com/downloads/de...=a8be8457-b0b6-455e-907e-d13be883adf2

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2:
http://www.microsoft.com/downloads/de...=a8be8457-b0b6-455e-907e-d13be883adf2

Microsoft Office SharePoint Server 2007 SP1 (32-bit editions):
http://www.microsoft.com/downloads/de...=862e6ad1-8124-4060-93b1-2b882ef5ce3d

Microsoft Office SharePoint Server 2007 SP2 (32-bit editions):
http://www.microsoft.com/downloads/de...=862e6ad1-8124-4060-93b1-2b882ef5ce3d

Microsoft Office SharePoint Server 2007 SP1 (64-bit editions):
http://www.microsoft.com/downloads/de...=b7b6e611-2c5d-4639-add9-972055789ecd

Microsoft Office SharePoint Server 2007 SP2 (64-bit editions):
http://www.microsoft.com/downloads/de...=b7b6e611-2c5d-4639-add9-972055789ecd

Provided and/or discovered by:
1) Carsten Eiram, Secunia Research.
2-4) The vendor credits Bing Liu, Fortinet.
5) TELUS Security Labs Vulnerability Research Team.
6) an anonymous person, reported via ZDI.
7) Independently reported by:
* Carsten Eiram, Secunia Research.
* Sean Larsson and Joshua Drake, VeriSign iDefense Labs.

Changelog:
2009-06-10: Added link to "Original Advisory" section.
2009-06-11: Added ZDI link to the "Original Advisory" section. Added additional vulnerability details to the advisory.
2009-06-12: Added iDefense link to the "Original Advisory" section.

Original Advisory:
MS09-021 (KB969462, KB969661, KB969679, KB969680, KB969681, KB969682, KB969683, KB969685, KB969686, KB969737, KB971822, KB971824):
http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx

Secunia Research:
http://secunia.com/secunia_research/2009-1/
http://secunia.com/secunia_research/2009-12/

TELUS Security Labs:
http://telussecuritylabs.com/threats/show/FSC20090609-01

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-09-040/

iDefense:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=805

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Adobe Flash Player Multiple Vulnerabilities // 58 views
2. TinyWebGallery Multiple URL Cross-Site Scripting // 29 views
3. Internet Explorer Multiple Vulnerabilities // 23 views
4. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 14 views
5. Sun Java JDK / JRE Multiple Vulnerabilities // 12 views
6. JBoss Web Console Cross-Site Scripting Vulnerabilities // 10 views
7. Adobe Reader/Acrobat Multiple Vulnerabilities // 10 views
8. Kaspersky Anti-Virus 2010 klavemu.kdl Denial of Service Vulnerability // 10 views
9. Microsoft Products GDI+ Multiple Vulnerabilities // 10 views
10. Sun Ray Server Software Multiple Vulnerabilities // 7 views