Vulnerability Name: | CVE-2008-3471 (CCN-45579) |
Assigned: | 2008-10-14 |
Published: | 2008-10-14 |
Updated: | 2022-02-09 |
Summary: | Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a BIFF file with a malformed record that triggers a user-influenced size calculation, aka "File Format Parsing Vulnerability."
|
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High |
|
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete | 9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete |
|
Vulnerability Type: | CWE-787
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2008-3471
Source: HP Type: Issue Tracking, Mailing List, Third Party Advisory SSRT080143
Source: CCN Type: SA32211 Microsoft Excel Multiple Vulnerabilities
Source: SECUNIA Type: Patch, Vendor Advisory 32211
Source: CCN Type: SECTRACK ID: 1021044 Microsoft Excel Object, Calendar, and Formula Bugs Let Remote Users Execute Arbitrary Code
Source: CCN Type: ASA-2008-410 MS08-057 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)
Source: CCN Type: Microsoft Security Bulletin MS11-096 Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241)
Source: CCN Type: Microsoft Security Bulletin MS12-028 Vulnerability in Microsoft Office Could Allow for Remote Code Execution (2639185)
Source: CCN Type: Microsoft Security Bulletin MS12-029 Vulnerability in Microsoft Word Could Allow Remote Code Execution (2680352)
Source: CCN Type: Microsoft Security Bulletin MS12-057 Vulnerability in Microsoft Office Could Allow for Remote Code Execution (2731879)
Source: CCN Type: Microsoft Security Bulletin MS12-064 Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2742319)
Source: CCN Type: Microsoft Security Bulletin MS12-065 Vulnerability in Microsoft Works Could Allow Remote Code Execution (KB2754670)
Source: CCN Type: Microsoft Security Bulletin MS12-079 Vulnerability in Microsoft Word Could Allow Remote Code Execution (2780642)
Source: CCN Type: Microsoft Security Bulletin MS13-043 Vulnerability in Microsoft Word Could Allow Remote Code Execution (2830399)
Source: CCN Type: Microsoft Security Bulletin MS13-072 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2845537)
Source: CCN Type: Microsoft Security Bulletin MS13-085 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080)
Source: CCN Type: Microsoft Security Bulletin MS13-086 Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2885084)
Source: CCN Type: Microsoft Security Bulletin MS14-001 Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2916605)
Source: CCN Type: Microsoft Security Bulletin MS14-017 Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2949660)
Source: CCN Type: Microsoft Security Bulletin MS14-034 Vulnerability in Microsoft Word Could Allow Remote Code Execution (2969261)
Source: CCN Type: Microsoft Security Bulletin MS14-061 Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3000434)
Source: CCN Type: Microsoft Security Bulletin MS14-069 Vulnerability in Microsoft Office Could Allow Remote Code Execution (3009710)
Source: CCN Type: Microsoft Security Bulletin MS14-081 Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3017301)
Source: CCN Type: Microsoft Security Bulletin MS14-083 Vulnerabilities in MicrosoftExcel Could Allow Remote Code Execution (3017347)
Source: CCN Type: Microsoft Security Bulletin MS15-081 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3080790)
Source: CCN Type: Microsoft Security Bulletin MS15-099 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664)
Source: CCN Type: Microsoft Security Bulletin MS15-110 Security Updates for Microsoft Office (3096440)
Source: CCN Type: Microsoft Security Bulletin MS15-116 Security Updates for Microsoft Office to Address Remote Code Execution (3104540)
Source: CCN Type: Microsoft Security Bulletin MS15-131 Security Update for Microsoft Office to Address Remote Code Execution (3116111)
Source: CCN Type: Microsoft Security Bulletin MS16-004 Security Update for Microsoft Office to Address Remote Code Execution - Critical (3124585)
Source: CCN Type: Microsoft Security Bulletin MS16-015 Security Update for Microsoft Office to Address Remote Code Execution (3134226)
Source: CCN Type: Microsoft Security Bulletin MS16-029 Security Update for Microsoft Office to Address Remote Code Execution (3141806)
Source: CCN Type: Microsoft Security Bulletin MS16-042 Security Update for Microsoft Office (3148775)
Source: CCN Type: Microsoft Security Bulletin MS16-054 Security Update for Microsoft Office (3155544)
Source: CCN Type: Microsoft Security Bulletin MS16-070 Security Update for Office (3163610)
Source: CCN Type: Microsoft Security Bulletin MS16-088 Security Updates for Office (3170008)
Source: CCN Type: Microsoft Security Bulletin MS16-099 Security Update for Office (3177451)
Source: CCN Type: Microsoft Security Bulletin MS16-107 Security Update for Microsoft Office (3185852)
Source: CCN Type: Microsoft Security Bulletin MS16-121 Security Update for Microsoft Office (3194063)
Source: CCN Type: Microsoft Security Bulletin MS16-133 Security Update for Microsoft Office (3199168)
Source: CCN Type: Microsoft Security Bulletin MS16-148 Security Update for Microsoft Office (3204068)
Source: CCN Type: Microsoft Security Bulletin MS17-002 Security Update for Microsoft Office (3214291)
Source: CCN Type: Microsoft Security Bulletin MS17-013 Security Update for Microsoft Graphics Component (4013075)
Source: CCN Type: Microsoft Security Bulletin MS17-014 Security Update for Microsoft Office (4013241)
Source: CCN Type: Microsoft Security Bulletin MS08-072 Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173)
Source: CCN Type: Microsoft Security Bulletin MS08-074 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070)
Source: CCN Type: Microsoft Security Bulletin MS08-057 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)
Source: CCN Type: Microsoft Security Bulletin MS09-009 Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (968557)
Source: CCN Type: Microsoft Security Bulletin MS09-017 Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (967340)
Source: CCN Type: Microsoft Security Bulletin MS09-021 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)
Source: CCN Type: Microsoft Security Bulletin MS09-024 Vulnerability in Microsoft Works Converters Could Allow Remote Code Execution (957632)
Source: CCN Type: Microsoft Security Bulletin MS09-027 Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514)
Source: CCN Type: Microsoft Security Bulletin MS09-067 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)
Source: CCN Type: Microsoft Security Bulletin MS09-068 Vulnerability in Microsoft Office Word Allows Remote Code Execution (976307)
Source: CCN Type: Microsoft Security Bulletin MS09-073 Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)
Source: CCN Type: Microsoft Security Bulletin MS10-004 Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (975416)
Source: CCN Type: Microsoft Security Bulletin MS10-017 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)
Source: CCN Type: Microsoft Security Bulletin MS10-036 Vulnerabilities in COM validation in Microsoft Office Could Allow Remote Code Execution (983235
Source: CCN Type: Microsoft Security Bulletin MS10-038 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452)
Source: CCN Type: Microsoft Security Bulletin MS10-056 Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638)
Source: CCN Type: Microsoft Security Bulletin MS10-057 Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707)
Source: CCN Type: Microsoft Security Bulletin MS10-079 Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194)
Source: CCN Type: Microsoft Security Bulletin MS10-087 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930)
Source: CCN Type: Microsoft Security Bulletin MS10-105 Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095)
Source: CCN Type: Microsoft Security Bulletin MS11-021 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2489279)
Source: CCN Type: Microsoft Security Bulletin MS11-023 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2489293)
Source: CCN Type: Microsoft Security Bulletin MS11-045 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2537146)
Source: CCN Type: Microsoft Security Bulletin MS11-072 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505)
Source: BID Type: Patch, Third Party Advisory, VDB Entry 31705
Source: CCN Type: BID-31705 Microsoft Excel BIFF File Format Parsing Remote Code Execution Vulnerability
Source: SECTRACK Type: Third Party Advisory, VDB Entry 1021044
Source: CERT Type: Third Party Advisory, US Government Resource TA08-288A
Source: VUPEN Type: Third Party Advisory ADV-2008-2808
Source: MISC Type: Third Party Advisory, VDB Entry http://www.zerodayinitiative.com/advisories/ZDI-08-068/
Source: MS Type: Patch, Vendor Advisory MS08-057
Source: XF Type: Third Party Advisory, VDB Entry excel-file-format-code-execution(45579)
Source: XF Type: UNKNOWN excel-biff-file-format-bo(45579)
Source: XF Type: Third Party Advisory, VDB Entry win-ms08kb956416-update(45581)
Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:5750
Source: CCN Type: ZDI-08-068 Microsoft Office Excel BIFF File Format Parsing Stack Overflow Vulnerability
|
Vulnerable Configuration: | Configuration 1: cpe:/a:microsoft:excel:2003:sp2:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2003:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2007:-:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2007:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:excel_viewer:-:*:*:*:*:*:*:*OR cpe:/a:microsoft:excel_viewer:2003:-:*:*:*:*:*:*OR cpe:/a:microsoft:excel_viewer:2003:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:office:2004:*:*:*:*:macos:*:*OR cpe:/a:microsoft:office:2008:*:*:*:*:macos:*:*OR cpe:/a:microsoft:office_compatibility_pack:2007:-:*:*:*:*:*:*OR cpe:/a:microsoft:office_compatibility_pack:2007:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:open_xml_file_format_converter:-:*:*:*:*:macos:*:* Configuration CCN 1: cpe:/a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2007:*:*:*:*:*:*:*OR cpe:/a:microsoft:office_compatibility_pack:2007:*:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2000:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2002:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2003:sp2:*:*:*:*:*:*OR cpe:/a:microsoft:excel_viewer:2003:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:excel_viewer:*:*:*:*:*:*:*:*OR cpe:/a:microsoft:office_compatibility_pack:2007:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2007:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2003:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:office:2004::~~~mac_os~~:*:*:*:*:* Denotes that component is vulnerable |
Oval Definitions |
|
BACK |