vendor:
Office 2003
by:
Giuseppe Gottardi
7,5
CVSS
HIGH
Stack/SEH Overflow
119
CWE
Product Name: Office 2003
Affected Version From: 11.5612.5606
Affected Version To: 11.8012.6568
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:office:2003
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Microsoft Office Excel 2003 Hlink Stack/SEH Overflow Exploit
This exploit was originally written by Manuel Santamarina Suarez, but it was working by clicking on the link and then on the 'Yes' button. In this version of exploit the author adds the RET address for Microsoft Office Excel 2003 (Italian; 11.5612.5606) and removed user confirmation by 'Yes' button. The exploit now simply works by clicking on the link.
Mitigation:
Apply the latest security patches and updates from Microsoft.