vendor:
Microsoft Works
by:
SecurityFocus
7.5
CVSS
HIGH
Buffer-overflow and Denial-of-Service
119, 20
CWE
Product Name: Microsoft Works
Affected Version From: 8
Affected Version To: 8
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:works
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
Microsoft Works Multiple Remote Vulnerabilities
The spreadsheet component of Microsoft Works is prone to multiple remote vulnerabilities, including buffer-overflow and denial-of service issues. These issues occur because the application fails to handle specifically crafted spreadsheet documents when importing them into Microsoft Works. These vulnerabilities allow remote attackers to execute arbitrary machine code in the context of affected application. Attackers may also crash vulnerable applications, denying service to legitimate users.
Mitigation:
Users should exercise caution when opening spreadsheet documents from untrusted sources. Administrators should consider disabling the import of spreadsheet documents into Microsoft Works.