Vulnerability Name: | CVE-2012-0185 (CCN-75118) | ||||||||
Assigned: | 2011-12-13 | ||||||||
Published: | 2012-05-08 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-0185 Source: CCN Type: SA49112 Microsoft Office Excel Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 49112 Source: CCN Type: Microsoft Security Bulletin MS12-030 Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2663830) Source: CCN Type: Microsoft Security Bulletin MS12-051 Vulnerability in Microsoft Office for Mac Could Allow Elevation of Privilege (2721015) Source: CCN Type: Microsoft Security Bulletin MS12-076 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2720184) Source: CCN Type: Microsoft Security Bulletin MS13-073 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2858300) Source: CCN Type: Microsoft Security Bulletin MS13-085 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080) Source: CCN Type: Microsoft Security Bulletin MS14-083 Vulnerabilities in MicrosoftExcel Could Allow Remote Code Execution (3017347) Source: CCN Type: Microsoft Security Bulletin MS16-054 Security Update for Microsoft Office (3155544) Source: CCN Type: Microsoft Security Bulletin MS16-070 Security Update for Office (3163610) Source: CCN Type: Microsoft Security Bulletin MS16-088 Security Updates for Office (3170008) Source: CCN Type: Microsoft Security Bulletin MS16-099 Security Update for Office (3177451) Source: CCN Type: Microsoft Security Bulletin MS16-107 Security Update for Microsoft Office (3185852) Source: CCN Type: Microsoft Security Bulletin MS16-121 Security Update for Microsoft Office (3194063) Source: CCN Type: Microsoft Security Bulletin MS16-133 Security Update for Microsoft Office (3199168) Source: CCN Type: Microsoft Security Bulletin MS16-148 Security Update for Microsoft Office (3204068) Source: CCN Type: Microsoft Security Bulletin MS17-002 Security Update for Microsoft Office (3214291) Source: CCN Type: Microsoft Security Bulletin MS17-013 Security Update for Microsoft Graphics Component (4013075) Source: CCN Type: Microsoft Security Bulletin MS17-014 Security Update for Microsoft Office (4013241) Source: CCN Type: BID-53376 Microsoft Excel 'MergeCells' Record Heap Overflow Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1027041 Source: CERT Type: US Government Resource TA12-129A Source: MS Type: UNKNOWN MS12-030 Source: XF Type: UNKNOWN ms-excel-mergecells-bo(75118) Source: XF Type: UNKNOWN ms-excel-mergecells-bo(75118) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:14738 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |