Overview
An unspecified vulnerability in Microsoft Excel may allow a remote attacker to execute arbitrary code.
Description
Microsoft Excel contains a vulnerability. According to Microsoft Security Bulletin MS07-015 The vulnerability is caused when Excel opens a specially crafted Excel file which will results in the access of memory outside intended regions when parsing placeholder data. |
Impact
By convincing a user to open a specially crafted Office document, an attacker could execute arbitrary code. |
Solution
Apply Update for Microsoft |
Do not open untrusted Office documents |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://www.microsoft.com/technet/security/advisory/932553.mspx
- http://www.microsoft.com/technet/security/Bulletin/MS07-015.mspx
- http://www.symantec.com/enterprise/security_response/weblog/2007/02/latest_office_zeroday_vulnerab.html
- http://secunia.com/advisories/24008/
- http://securitytracker.com/alerts/2007/Feb/1017584.html
- http://www.securityfocus.com/bid/22383
Acknowledgements
This vulnerability was reported in Microsoft Security Advisory (932553).
This document was written by Jeff Gennari based on information from Microsoft.
Other Information
CVE IDs: | CVE-2007-0671 |
Severity Metric: | 24.98 |
Date Public: | 2007-02-02 |
Date First Published: | 2007-02-05 |
Date Last Updated: | 2007-03-13 19:09 UTC |
Document Revision: | 20 |