vendor:
Excel
by:
Luigi Auriemma
7.8
CVSS
HIGH
Use-After-Free
416
CWE
Product Name: Excel
Affected Version From: Office 2003 11.8335.8333 SP3
Affected Version To: Office 2003 11.8335.8333 SP3
Patch Exists: Yes
Related CWE: N/A
CPE: a:microsoft:excel
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2011
Microsoft Excel Use-After-Free Vulnerability
Excel 2003 is a spreadsheet program, part of the Office 2003 suite still supported by Microsoft. Use-after-free probably located in the code that handles the vbscript macros. How to replicate: open the proof-of-concept via web or manually, select No when prompted with 'An error occurred while loading 'Module1'. Do you want to continue loading the project?', select OK when prompted with 'Unexpected error (32790)', select Yes or No when prompted with 'Excel found unreadable content in ...'
Mitigation:
Update to the latest version of Microsoft Excel