Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office SharePoint Server 2007 Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file containing a formula within a cell, aka "Formula Parsing Vulnerability."
Vector
NETWORK
Complexity
MEDIUM
Authentication
NONE
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE
Microsoft Office sharepoint server 2007 Sp1 X64 (not an official CPE)
Microsoft Office sharepoint server 2007 Sp1 (not an official CPE)
Microsoft Office sharepoint server 2007 (not an official CPE)
Microsoft Office excel viewer 2003 Sp3 (not an official CPE)
Microsoft Office excel viewer (not an official CPE)
Microsoft Office excel viewer 2003 (not an official CPE)
Microsoft Office compatibility pack for word excel ppt 2007 Sp1 (not an official CPE)
Microsoft Office compatibility pack for word excel ppt 2007 (not an official CPE)
Microsoft Office 2008 Mac
Microsoft Office XP Service Pack 3
Microsoft Office 2007 Service Pack 1
Microsoft Office 2007
Microsoft Office 2004 Mac
Microsoft Office 2003 Service Pack 3
Microsoft Office 2000 sp3
Microsoft Office 2003 sp2
Microsft Open xml file format converter Unknown Mac (not an official CPE)
Microsoft Office sharepoint server 2007 Unknown X64 (not an official CPE)
Advisory | Patch | Confirmed | Link |
---|---|---|---|
HPSBST02379 | |||
31706 | |||
1021044 | |||
TA08-288A | |||
ADV-2008-2808 | |||
MS08-057 | |||
excel-rept-code-execution(45580) | |||
win-ms08kb956416-update(45581) |
KB955461 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB955464 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB955466 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB955468 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB955470 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB955935 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB955936 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB955937 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB958267 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB958304 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
KB958312 | MS08-057 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution