Oval Definition:oval:org.mitre.oval:def:8479
Revision Date:2014-06-30Version:16
Title:Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability
Description:Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-0261
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Excel 2007
Microsoft Office Compatibility Pack
Definition Synopsis
  • Vulnerable Excel 2007
  • Microsoft Excel 2007 is installed
  • AND Excel.exe version is less than 12.0.6524.5003
  • OR Vulnerable Compatibility Pack, Office 2007
  • Microsoft Office Compatibility Pack is installed
  • OR Microsoft Office 2007 is installed
  • AND Excelcnv.exe version is less than 12.0.6529.5000
  • BACK