Vulnerability Name:
CVE-2004-0846 (CCN-17653)
Assigned:
2004-10-12
Published:
2004-10-12
Updated:
2018-10-12
Summary:
Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
CVSS v3 Severity:
7.3 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
Low
Availibility (A):
Low
CVSS v2 Severity:
7.5 High
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
7.5 High
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2004-0846
Source: BUGTRAQ
Type: UNKNOWN
20041013 Buffer Overflow In Microsoft Excel
Source: CCN
Type: SA12800
Microsoft Excel Buffer Overflow Vulnerability
Source: SECUNIA
Type: UNKNOWN
12800
Source: CCN
Type: Microsoft Security Bulletin MS11-096
Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241)
Source: CCN
Type: Microsoft Security Bulletin MS12-028
Vulnerability in Microsoft Office Could Allow for Remote Code Execution (2639185)
Source: CCN
Type: Microsoft Security Bulletin MS12-029
Vulnerability in Microsoft Word Could Allow Remote Code Execution (2680352)
Source: CCN
Type: Microsoft Security Bulletin MS12-034
Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578)
Source: CCN
Type: Microsoft Security Bulletin MS12-057
Vulnerability in Microsoft Office Could Allow for Remote Code Execution (2731879)
Source: CCN
Type: Microsoft Security Bulletin MS12-064
Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2742319)
Source: CCN
Type: Microsoft Security Bulletin MS12-065
Vulnerability in Microsoft Works Could Allow Remote Code Execution (KB2754670)
Source: CCN
Type: Microsoft Security Bulletin MS12-070
Vulnerability in SQL Server Could Allow Elevation of Privilege (2754849)
Source: CCN
Type: Microsoft Security Bulletin MS12-079
Vulnerability in Microsoft Word Could Allow Remote Code Execution (2780642)
Source: CCN
Type: Microsoft Security Bulletin MS13-022
Vulnerability in Silverlight Could Allow Remote Code Execution (2814124)
Source: CCN
Type: Microsoft Security Bulletin MS13-043
Vulnerability in Microsoft Word Could Allow Remote Code Execution (2830399)
Source: CCN
Type: Microsoft Security Bulletin MS13-054
Vulnerability in Windows Components Could Allow Remote Code Execution (2848295)
Source: CCN
Type: Microsoft Security Bulletin MS13-072
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2845537)
Source: CCN
Type: Microsoft Security Bulletin MS13-085
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080)
Source: CCN
Type: Microsoft Security Bulletin MS13-086
Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2885084)
Source: CCN
Type: Microsoft Security Bulletin MS14-001
Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2916605)
Source: CCN
Type: Microsoft Security Bulletin MS14-017
Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2949660)
Source: CCN
Type: Microsoft Security Bulletin MS14-034
Vulnerability in Microsoft Word Could Allow Remote Code Execution (2969261)
Source: CCN
Type: Microsoft Security Bulletin MS14-038
Vulnerability in Windows Journal Could Allow Remote Code Execution (2975689)
Source: CCN
Type: Microsoft Security Bulletin MS14-044
Vulnerabilities in SQL Server Could Allow Elevation of Privilege (2984340)
Source: CCN
Type: Microsoft Security Bulletin MS14-061
Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3000434)
Source: CCN
Type: Microsoft Security Bulletin MS14-069
Vulnerability in Microsoft Office Could Allow Remote Code Execution (3009710)
Source: CCN
Type: Microsoft Security Bulletin MS14-081
Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3017301)
Source: CCN
Type: Microsoft Security Bulletin MS14-083
Vulnerabilities in MicrosoftExcel Could Allow Remote Code Execution (3017347)
Source: CCN
Type: Microsoft Security Bulletin MS15-081
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3080790)
Source: CCN
Type: Microsoft Security Bulletin MS15-099
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664)
Source: CCN
Type: Microsoft Security Bulletin MS15-110
Security Updates for Microsoft Office (3096440)
Source: CCN
Type: Microsoft Security Bulletin MS15-116
Security Updates for Microsoft Office to Address Remote Code Execution (3104540)
Source: CCN
Type: Microsoft Security Bulletin MS15-131
Security Update for Microsoft Office to Address Remote Code Execution (3116111)
Source: CCN
Type: Microsoft Security Bulletin MS16-004
Security Update for Microsoft Office to Address Remote Code Execution - Critical (3124585)
Source: CCN
Type: Microsoft Security Bulletin MS16-015
Security Update for Microsoft Office to Address Remote Code Execution (3134226)
Source: CCN
Type: Microsoft Security Bulletin MS16-029
Security Update for Microsoft Office to Address Remote Code Execution (3141806)
Source: CCN
Type: Microsoft Security Bulletin MS16-042
Security Update for Microsoft Office (3148775)
Source: CCN
Type: Microsoft Security Bulletin MS16-054
Security Update for Microsoft Office (3155544)
Source: CCN
Type: Microsoft Security Bulletin MS16-070
Security Update for Office (3163610)
Source: CCN
Type: Microsoft Security Bulletin MS16-088
Security Updates for Office (3170008)
Source: CCN
Type: Microsoft Security Bulletin MS16-099
Security Update for Office (3177451)
Source: CCN
Type: Microsoft Security Bulletin MS16-107
Security Update for Microsoft Office (3185852)
Source: CCN
Type: Microsoft Security Bulletin MS16-121
Security Update for Microsoft Office (3194063)
Source: CCN
Type: Microsoft Security Bulletin MS16-133
Security Update for Microsoft Office (3199168)
Source: CCN
Type: Microsoft Security Bulletin MS16-148
Security Update for Microsoft Office (3204068)
Source: CCN
Type: Microsoft Security Bulletin MS17-002
Security Update for Microsoft Office (3214291)
Source: CCN
Type: Microsoft Security Bulletin MS17-013
Security Update for Microsoft Graphics Component (4013075)
Source: CCN
Type: Microsoft Security Bulletin MS17-014
Security Update for Microsoft Office (4013241)
Source: CCN
Type: CIAC Information Bulletin P-009
Microsoft Excel Vulnerability Could Allow Remote Code Execution
Source: CIAC
Type: Vendor Advisory
P-009
Source: CCN
Type: US-CERT VU#274496
Microsoft Excel parameter validation error
Source: CERT-VN
Type: Patch, Third Party Advisory, US Government Resource
VU#274496
Source: CCN
Type: Microsoft Security Bulletin MS04-033
Vulnerability in Microsoft Excel Could Allow Remote Code Execution (886836)
Source: CCN
Type: Microsoft Security Bulletin MS06-012
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (905413)
Source: CCN
Type: Microsoft Security Bulletin MS06-037
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (917285)
Source: CCN
Type: Microsoft Security Bulletin MS06-059
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (924164)
Source: CCN
Type: Microsoft Security Bulletin MS07-002
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (927198)
Source: CCN
Type: Microsoft Security Bulletin MS07-023
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (934233)
Source: CCN
Type: Microsoft Security Bulletin MS07-036
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (936542)
Source: CCN
Type: Microsoft Security Bulletin MS07-044
Vulnerability in Microsoft Excel Could Allow Remote Code Execution (940965)
Source: CCN
Type: Microsoft Security Bulletin MS08-014
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (949029)
Source: CCN
Type: Microsoft Security Bulletin MS08-026
Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (951207)
Source: CCN
Type: Microsoft Security Bulletin MS08-042
Vulnerability in Microsoft Word Could Allow Remote Code Execution (955048)
Source: CCN
Type: Microsoft Security Bulletin MS08-043
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (954066)
Source: CCN
Type: Microsoft Security Bulletin MS08-051
Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785)
Source: CCN
Type: Microsoft Security Bulletin MS08-052
Vulnerabilities in GDI+ Could Allow Remote Code Execution (954593)
Source: CCN
Type: Microsoft Security Bulletin MS08-057
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)
Source: CCN
Type: Microsoft Security Bulletin MS09-004
Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420)
Source: CCN
Type: Microsoft Security Bulletin MS09-017
Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (967340)
Source: CCN
Type: Microsoft Security Bulletin MS09-021
Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)
Source: CCN
Type: Microsoft Security Bulletin MS09-062
Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)
Source: CCN
Type: Microsoft Security Bulletin MS09-067
Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)
Source: CCN
Type: Microsoft Security Bulletin MS10-003
Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution (978214)
Source: CCN
Type: Microsoft Security Bulletin MS10-004
Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (975416)
Source: CCN
Type: Microsoft Security Bulletin MS10-017
Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)
Source: CCN
Type: Microsoft Security Bulletin MS10-028
Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (980094)
Source: CCN
Type: Microsoft Security Bulletin MS10-036
Vulnerabilities in COM validation in Microsoft Office Could Allow Remote Code Execution (983235
Source: CCN
Type: Microsoft Security Bulletin MS10-038
Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452)
Source: CCN
Type: Microsoft Security Bulletin MS10-056
Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638)
Source: CCN
Type: Microsoft Security Bulletin MS10-057
Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707)
Source: CCN
Type: Microsoft Security Bulletin MS10-079
Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194)
Source: CCN
Type: Microsoft Security Bulletin MS10-087
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930)
Source: CCN
Type: Microsoft Security Bulletin MS10-105
Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095)
Source: CCN
Type: Microsoft Security Bulletin MS11-008
Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2451879)
Source: CCN
Type: Microsoft Security Bulletin MS11-021
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2489279)
Source: CCN
Type: Microsoft Security Bulletin MS11-023
Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2489293)
Source: CCN
Type: Microsoft Security Bulletin MS11-029
Vulnerability in GDI+ Could Allow Remote Code Execution (2489979)
Source: CCN
Type: Microsoft Security Bulletin MS11-045
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2537146)
Source: CCN
Type: Microsoft Security Bulletin MS11-049
Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893)
Source: CCN
Type: Microsoft Security Bulletin MS11-060
Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2560978)
Source: CCN
Type: Microsoft Security Bulletin MS11-072
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505)
Source: CCN
Type: BID-11373
Microsoft Excel File Handler Buffer Overflow Vulnerability
Source: MS
Type: UNKNOWN
MS04-033
Source: XF
Type: UNKNOWN
excel-execute-code(17653)
Source: XF
Type: UNKNOWN
excel-execute-code(17653)
Source: XF
Type: UNKNOWN
excel-ms04033-patch(17683)
Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:2673
Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:4226
Vulnerable Configuration:
Configuration 1
:
cpe:/a:microsoft:excel:2000:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:excel:2001:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:excel:2002:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:excel:x:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:office:2000:sp3:*:*:*:*:*:*
OR
cpe:/a:microsoft:office:2001:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:office:v.x:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:microsoft:excel:2000:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:excel:2002:*:*:*:*:*:*:*
AND
cpe:/a:microsoft:office:2001:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:office:xp:sp2:*:*:*:*:*:*
OR
cpe:/a:microsoft:office:2000:sp3:*:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.mitre.oval:def:2673
V
Excel 2000 File Handler Code Execution Vulnerability
2012-05-28
oval:org.mitre.oval:def:4226
V
Excel 2002 File Handler Code Execution Vulnerability
2012-05-28
BACK
microsoft
excel 2000
microsoft
excel 2001
microsoft
excel 2002
microsoft
excel x
microsoft
office 2000 sp3
microsoft
office 2001
microsoft
office v.x
microsoft
excel 2000
microsoft
excel 2002
microsoft
office 2001
microsoft
office xp sp2
microsoft
office 2000 sp3