vendor:
Microsoft Excel
by:
Unknown
7.5
CVSS
HIGH
Remote code execution
119
CWE
Product Name: Microsoft Excel
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:microsoft:excel
Platforms Tested: Windows
Unknown
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel is susceptible to a remote code-execution vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input data in the 'Named Range' definition in Excel data files. This results in the corruption of critical memory sections, allowing code execution.
Mitigation:
Apply the latest security patches from Microsoft. Avoid opening Excel files from untrusted sources.