vendor:
Office 2007
by:
webDEViL
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Office 2007
Affected Version From: 12.0.4518.1014
Affected Version To: 12.0.4518.1014
Patch Exists: YES
Related CWE: CVE-2010-0822
CPE: a:microsoft:office:2007
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2010
Exploit for MS10-038/CVE-2010-0822
This is an exploit for MS10-038/CVE-2010-0822. It is a buffer overflow exploit that is hardcoded for Windows XP SP3. The exploit is in the form of an Excel file, which is hosted on krash.in. The Office 2007 version is 12.0.4518.1014, although the MS10-038 bulletin states that Office 2007 is not vulnerable. The exploit is written in Python and uses binascii to convert a hex string to a binary string.
Mitigation:
Microsoft released a patch for this vulnerability in 2010. Users should ensure that their systems are up to date with the latest security patches.