vendor:
Microsoft Excel
by:
Google Security Research
7,8
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: Microsoft Excel
Affected Version From: Microsoft Excel 2007
Affected Version To: Microsoft Excel 2013
Patch Exists: Yes
Related CWE: N/A
CPE: microsoft:excel
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2003 R2, Windows 7 x86, Windows 8.1 x86
2014
Microsoft Excel 2007/2010/2013 Memory Corruption Vulnerability
This vulnerability was observed in Microsoft Excel 2007 running on Windows 2003 R2. This crash was also reproduced in Microsoft Excel 2010 on Windows 7 x86 and Microsoft Excel 2013 on Windows 8.1 x86. The test environment was Excel 2007 on Windows 2003 R2 with application verifier basic checks enabled. The minimized crashing file shows two deltas from the original. The first at offset 0x237 is in the data of the 4th BIFFRecord and the second delta at offset 0x34a5 is in the type field of a BIFFRecord.
Mitigation:
Apply the latest security patches and updates to the affected software.