Vulnerability Name: | CVE-2010-0258 (CCN-56464) | ||||||||
Assigned: | 2010-03-09 | ||||||||
Published: | 2010-03-09 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that causes memory to be interpreted as a different object type than intended, aka "Microsoft Office Excel Sheet Object Type Confusion Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0258 Source: IDEFENSE Type: UNKNOWN 20100309 Microsoft Excel Sheet Object Type Confusion Vulnerability Source: CCN Type: SA38805 Microsoft Office Excel Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1023698 Microsoft Office Excel Bugs Let Remote Users Execute Arbitrary Code Source: CCN Type: Microsoft Security Bulletin MS10-017 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150) Source: CCN Type: Microsoft Security Bulletin MS10-038 Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452) Source: CCN Type: Microsoft Security Bulletin MS10-057 Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707) Source: CCN Type: BID-38550 Microsoft Excel Object Type Confusion Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1023698 Source: CERT Type: US Government Resource TA10-068A Source: MS Type: UNKNOWN MS10-017 Source: XF Type: UNKNOWN excel-objecttype-code-execution(56464) Source: CCN Type: iDefense Labs Public Advisory: 03.09.10 Microsoft Excel Sheet Object Type Confusion Vulnerability Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:8545 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |