CVE-2008-0112
Microsoft Excel - Code Execution (MS08-014)
Severity Score
9.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."
Vulnerabilidad no especificada en Microsoft Excel 2000 SP3 y Office para Mac 2004 y 2008 permite a atacantes remotos con la complicidad del usuario ejecutar código de su elección mediante un fichero .SLK manipulado que no es gestionado adecuadamente en la importación del fichero, también conocido como "Vulnerabilidad de Importación de Fichero Excel (Excel File Import Vulnerability)."
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-01-07 CVE Reserved
- 2008-03-11 CVE Published
- 2008-03-21 First Exploit
- 2024-08-07 CVE Updated
- 2024-09-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (8)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/5287 | 2008-03-21 |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/28095 | 2018-10-12 | |
http://www.us-cert.gov/cas/techalerts/TA08-071A.html | 2018-10-12 |
URL | Date | SRC |
---|---|---|
http://marc.info/?l=bugtraq&m=120585858807305&w=2 | 2018-10-12 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-014 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2000 Search vendor "Microsoft" for product "Excel" and version "2000" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Search vendor "Microsoft" for product "Office" | 2004 Search vendor "Microsoft" for product "Office" and version "2004" | mac |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Search vendor "Microsoft" for product "Office" | 2008 Search vendor "Microsoft" for product "Office" and version "2008" | mac |
Affected
|