Content
(MS10-017) Microsoft Office Excel Record Memory Corruption Vulnerability (980150)
- Type
- Buffer Overflow
- Impact of exploitation
- Remote Code Execution
- User Interaction
- user interaction is needed
- Attack Vector
- Maliciously Crafted File
- Rating
- Medium
- CVE reference
- CVE-2010-0257,
- Vendor Status
- Responded and patched
- Vulnerable systems
- Excel 2002 SP3,
- Excel 2003 SP3,
- Excel 2007 SP1,
- Summary
- A remote code execution vulnerability exists in the way that Microsoft Office Excel handles specially crafted Excel files.
Tab Navigation
Description
A remote code execution vulnerability exists in the way that Microsoft Office Excel handles specially crafted Excel files. When successfully exploited the attacker could take complete control of the affected system and run remote code.
McAfee Product Mitigation & Recommendations
Recommendations
The vendor has released an update to address this issue http://www.microsoft.com/technet/security/bulletin/ms10-017.mspx
McAfee Product Mitigation
McAfee Foundstone
- Signature:
- (MS10-017) Microsoft Office Excel Record Memory Corruption Vulnerability (980150)
- Signature identifier:
- 8106
- Release date:
- 3/9/2010
Additional Resources
Microsoft Security Bulletin MS10-017 - Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)
http://www.microsoft.com/technet/security/bulletin/ms10-017.mspx
All Information
Timeline -
3/10/2010
A proof of concept has been released.
3/9/2010
Vendor has provided a patch.
Description -
A remote code execution vulnerability exists in the way that Microsoft Office Excel handles specially crafted Excel files. When successfully exploited the attacker could take complete control of the affected system and run remote code.
McAfee Product Mitigation & Recommendations
Recommendations -
The vendor has released an update to address this issue http://www.microsoft.com/technet/security/bulletin/ms10-017.mspx
McAfee Product Mitigation
McAfee Foundstone
- Signature:
- (MS10-017) Microsoft Office Excel Record Memory Corruption Vulnerability (980150)
- Signature identifier:
- 8106
- Release date:
- 3/9/2010
Additional Resources
Additional Resources -
Microsoft Security Bulletin MS10-017 - Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)
http://www.microsoft.com/technet/security/bulletin/ms10-017.mspx