Summary
This host is missing a critical security update according to Microsoft Bulletin MS09-067.
Impact
Successful exploitation could execute arbitrary code on the remote system and corrupt memory, buffer overflow via a specially crafted Excel file.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/MS09-067
Insight
- An error in the parsing of Excel spreadsheets can be exploited to corrupt memory via a specially crafted Excel file.
- An error in the processing of certain record objects can be exploited to corrupt memory via a specially crafted Excel file.
- Another error in the processing of certain record objects can be exploited to corrupt memory via a specially crafted Excel file.
- An error in the processing of Binary File Format (BIFF) records can be exploited to cause a heap-based buffer overflow via a specially crafted Excel file.
- An error in the handling of formulas embedded inside a cell can be exploited to corrupt memory via a specially crafted Excel file.
- An error when loading Excel formulas can be exploited to corrupt a pointer when a specially crafted Excel file is being opened.
- An error when loading Excel records can be exploited to corrupt memory via a specially crafted Excel file.
- An error when processing Excel record objects can be exploited via a specially crafted Excel file.
Affected
Microsoft Excel Viewer 2003/2007
Microsoft Office Excel 2002/2003/2007
Microsoft Office Compatibility Pack for Word,Excel,PowerPoint 2007 File Formats SP 1/2
References
Severity
Classification
-
CVE CVE-2009-3127, CVE-2009-3128, CVE-2009-3129, CVE-2009-3130, CVE-2009-3131, CVE-2009-3132, CVE-2009-3133, CVE-2009-3134 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Consent User Interface Privilege Escalation Vulnerability (2442962)
- Microsoft .NET Framework Multiple Vulnerabilities (2861561)
- Microsoft Foundation Classes Could Allow Remote Code Execution Vulnerability (2387149)
- Microsoft Active Accessibility Remote Code Execution Vulnerability (2623699)
- Microsoft .NET Framework Remote Code Execution Vulnerability (2484015)