header-logo
Suggest Exploit
vendor:
Excel
by:
Unknown
7.5
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: Excel
Affected Version From: Excel 2002 SP3
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:microsoft:excel:2002:sp3
Metasploit:
Other Scripts:
Platforms Tested:
Unknown

Microsoft Excel HFPicture Record Parsing Memory Corruption (0day)

This exploit targets a memory corruption vulnerability in Microsoft Excel's HFPicture Record parsing. It allows an attacker to corrupt memory and potentially execute arbitrary code.

Mitigation:

Apply the latest security patches provided by Microsoft.
Source

Exploit-DB raw data:

'''
  __  __  ____         _    _ ____ 
 |  \/  |/ __ \   /\  | |  | |  _ \
 | \  / | |  | | /  \ | |  | | |_) |
 | |\/| | |  | |/ /\ \| |  | |  _ <  (day 23 0day binary anlysis)
 | |  | | |__| / ____ \ |__| | |_) |
 |_|  |_|\____/_/    \_\____/|____/

'''
 
  Title               :  Microsoft Excel HFPicture Record Parsing Memory Corruption (0day)
  Version             :  Excel 2002 SP3
  Analysis            :  http://www.abysssec.com
  Vendor              :  http://www.microsoft.com
  Impact              :  High
  Contact             :  shahin [at] abysssec.com , info  [at] abysssec.com
  Twitter             :  @abysssec
  CVE                 :  NO CVE
 
here is BA : http://www.exploit-db.com/moaub-23-microsoft-office-excel-2002-memory-corruption-vulnerability-0day/
here is the PoC : https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/15088.zip (moaub-23-excel-poc.zip)