Oval Definition:oval:org.mitre.oval:def:5878
Revision Date:2014-06-30Version:19
Title:Excel Field Sanitization Vulnerability
Description:Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel Field Sanitization Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-3134
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Excel 2002
Microsoft Excel 2003
Microsoft Excel 2007
Microsoft Office Compatibility Pack
Microsoft Office Excel Viewer
Microsoft Office Excel Viewer 2003
Definition Synopsis
  • AND
  • Microsoft Excel 2002 is installed
  • AND Excel.exe version is less than 10.0.6856.0
  • OR
  • Microsoft Excel 2003 is installed
  • AND Excel.exe version is less than 11.0.8316.0
  • OR
  • Microsoft Excel 2007 is installed
  • AND Excel.exe version is less than 12.0.6514.5000
  • OR
  • Microsoft Excel Viewer 2003 is installed
  • AND Xlview.exe version is less than 11.0.8313.0
  • OR
  • Microsoft Excel Viewer 2007 is installed
  • AND Xlview.exe version is less than 12.0.6514.5000
  • OR
  • Microsoft Office Compatibility Pack is installed
  • OR Microsoft Excel 2007 is installed
  • AND Excelcnv.exe version is less than 12.0.6514.5000
  • BACK