Vulnerability Name: | CVE-2008-3006 (CCN-44091) | ||||||||
Assigned: | 2008-08-12 | ||||||||
Published: | 2008-08-12 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 Gold and SP3; Office Excel Viewer; Office Compatibility Pack 2007 Gold and SP1; Office SharePoint Server 2007 Gold and SP1; and Office 2004 and 2008 for Mac do not properly parse Country record values when loading Excel files, which allows remote attackers to execute arbitrary code via a crafted Excel file, aka the "Excel Record Parsing Vulnerability." This vulnerability has multiple attack vectors and CIA impact. Please review the following guidance from Microsoft for more information: An attack against a user's local Excel client can result in remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system remotely. An attacker could then install programs or view, change, or delete data; or create new accounts with full user rights. An attack against a Microsoft Office SharePoint Server 2007 site can result in elevation of privilege. An attacker who successfully exploited this vulnerability could gain an elevation of privilege within SharePoint server, as opposed to elevation of privilege within the workstation or server environment. In an attack against a SharePoint site, an attacker would first need an account on the SharePoint site with sufficient rights to upload a specially crafted Excel file and then create a web part using the file on the SharePoint site. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-399 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-3006 Source: HP Type: UNKNOWN HPSBST02360 Source: CCN Type: SA31454 Microsoft Office Excel Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 31454 Source: CCN Type: SA31455 Microsoft Office SharePoint Server Privilege Escalation Vulnerability Source: SECUNIA Type: Vendor Advisory 31455 Source: CCN Type: SECTRACK ID: 1020672 Microsoft Excel Input Validation Bug in Parsing Records Lets Remote Users Execute Arbitrary Code Source: CCN Type: Microsoft Security Bulletin MS08-043 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (954066) Source: CCN Type: Microsoft Security Bulletin MS08-057 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416) Source: CCN Type: Microsoft Security Bulletin MS09-021 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462) Source: CCN Type: Microsoft Security Bulletin MS09-067 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652) Source: CCN Type: Microsoft Security Bulletin MS10-017 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150) Source: CCN Type: Microsoft Security Bulletin MS10-038 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452) Source: CCN Type: Microsoft Security Bulletin MS10-057 Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707) Source: BUGTRAQ Type: UNKNOWN 20080812 ZDI-08-048: Microsoft Excel COUNTRY Record Memory Corruption Vulnerability Source: BID Type: UNKNOWN 30640 Source: CCN Type: BID-30640 Microsoft Excel Record Parsing Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1020672 Source: CERT Type: US Government Resource TA08-225A Source: VUPEN Type: Vendor Advisory ADV-2008-2347 Source: MISC Type: UNKNOWN http://www.zerodayinitiative.com/advisories/ZDI-08-048/ Source: MS Type: UNKNOWN MS08-043 Source: XF Type: UNKNOWN excel-record-value-code-execution(44091) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5561 Source: CCN Type: ZDI-08-048 Microsoft Excel COUNTRY Record Memory Corruption Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |