vendor:
Excel
by:
Shahin, Abysssec
N/A
CVSS
N/A
Stack Overflow
119
CWE
Product Name: Excel
Affected Version From: Excel 2002 and XP (SP3)
Affected Version To: Excel 2002 and XP (SP3)
Patch Exists: YES
Related CWE: CVE-2010-0822
CPE: a:microsoft:excel
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
Microsoft Excel OBJ Record Stack Overflow
A stack-based buffer overflow vulnerability exists in Microsoft Excel 2002 and XP (SP3). An attacker can exploit this vulnerability by sending a specially crafted Excel file to the victim. When the victim opens the file, the attacker's code will be executed in the context of the current user. This can potentially allow the attacker to execute arbitrary code on the victim's machine.
Mitigation:
Microsoft has released a patch to address this vulnerability.