Vulnerability Name: | CVE-2009-3128 (CCN-54005) | ||||||||
Assigned: | 2009-11-10 | ||||||||
Published: | 2009-11-10 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3128 Source: CCN Type: SA37299 Microsoft Excel Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1023157 Microsoft Excel Bugs Let Remote Users Execute Arbitrary Code Source: CCN Type: Microsoft Security Bulletin MS09-067 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652) Source: CCN Type: Microsoft Security Bulletin MS10-017 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150) Source: CCN Type: Microsoft Security Bulletin MS10-038 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452) Source: CCN Type: Microsoft Security Bulletin MS10-057 Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707) Source: CCN Type: BID-36944 Microsoft Excel 'SxView' Memory Corruption Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1023157 Source: CERT Type: US Government Resource TA09-314A Source: MS Type: UNKNOWN MS09-067 Source: XF Type: UNKNOWN excel-sxview-code-execution(54005) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:6474 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |