vendor:
Microsoft Excel
by:
LifeAsaGeek
7.5
CVSS
HIGH
Heap Overflow
122
CWE
Product Name: Microsoft Excel
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
MS07-002 EXCEL Malformed Palette Record Vulnerability DOS POC
Bound error occurs when parsing Palette Record and it causes Heap Overflow. The attack vector is through arbitrary data overwrite to the heap. The result of the heap overflow is denial of service (DOS). The pyExcelerator module needs to be modified to prevent the generation of Palette Record.
Mitigation:
Modify the pyExcelerator module to prevent the generation of Palette Record.