CVE-2008-0113
Microsoft Excel BIFF File Format Cell Record Parsing Memory Corruption Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
Una vulnerabilidad no especificada en Microsoft Office Excel Viewer 2003 hasta SP3, permite a atacantes remotos asistidos por el usuario ejecutar código arbitrario por medio de un documento de Excel con comentarios de celda malformada que desencadenan la corrupción de memoria a partir de un "allocation error," también se conoce como "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file.
The specific flaw exists within the parsing of malformed cell comments. When Excel encounters a malformed record it attempts to rebuild the broken meta-data. A flaw in this rebuilding process allows the user to specify critical data offsets eventually leading to code execution under the logged in users credentials.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-01-07 CVE Reserved
- 2008-03-11 CVE Published
- 2008-03-30 First Exploit
- 2024-08-07 CVE Updated
- 2024-10-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/489415/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1019578 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA08-071A.html | Third Party Advisory | |
http://www.zerodayinitiative.com/advisories/ZDI-08-008 | X_refsource_misc | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5421 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/5320 | 2008-03-30 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://marc.info/?l=bugtraq&m=120585858807305&w=2 | 2018-10-15 | |
http://secunia.com/advisories/29321 | 2018-10-15 | |
http://www.vupen.com/english/advisories/2008/0848/references | 2018-10-15 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-016 | 2018-10-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Excel Viewer Search vendor "Microsoft" for product "Excel Viewer" | 2003 Search vendor "Microsoft" for product "Excel Viewer" and version "2003" | - |
Affected
|