vendor:
MS Excel
by:
Sean Larsson
7.5
CVSS
HIGH
Malformed FEATHEADER Record
CWE
Product Name: MS Excel
Affected Version From: MS Office 2003
Affected Version To: MS Office 2007
Patch Exists: YES
Related CWE: CVE-2009-3129
CPE: a:microsoft:excel:2003, cpe:/a:microsoft:excel:2007
Platforms Tested: Windows XP SP2
2009
MS Excel Malformed FEATHEADER Record Exploit
This exploit targets a vulnerability in MS Excel which allows an attacker to execute arbitrary code by exploiting a malformed FEATHEADER record. The vulnerability has been assigned CVE-2009-3129 and is covered by the Microsoft security bulletin MS09-067. The affected versions of MS Office are 2003 and 2007. The exploit has been tested on Windows XP SP2 with MS Office 2003 v. 11.5604.5606. The original discovery of this exploit was made by Sean Larsson.
Mitigation:
Apply the security patch provided by Microsoft in the MS09-067 security bulletin. This will fix the vulnerability and prevent exploitation.