vendor:
Office 2007
by:
Google Security Research
8,8
CVSS
HIGH
Microsoft Office 2007 Excel Memory Corruption
119
CWE
Product Name: Office 2007
Affected Version From: Microsoft Office 2007 Excel
Affected Version To: Microsoft Office 2007 Excel
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:office:2007
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2014
Microsoft Office 2007 Excel Memory Corruption
A memory corruption vulnerability was discovered in Microsoft Office 2007 Excel when the Microsoft Office File Validation Add-In was disabled and Application Verifier was enabled for testing and reproduction. The vulnerability was triggered by a one bit delta from the original file at offset 0x139F. The crashing eip was observed 4 times in fuzzing results with various invalid memory address being dereferenced.
Mitigation:
Microsoft Office File Validation Add-In should be enabled and Application Verifier should be disabled.