Microsoft Excel Memory Access Error Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1017485
|
|
SecurityTracker URL: http://securitytracker.com/id?1017485
|
|
CVE Reference: CVE-2007-0028
(Links to External Site)
|
Updated: Jan 10 2007
|
Original Entry Date: Jan 9 2007
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Microsoft Security Advisory
|
Version(s): Excel 2000, 2002, 2003, Excel Viewer 2003; Works Suite 2004, 2005, and 2006; Office 2004 for Mac, Office v. X for Mac
|
Description: A vulnerability was reported in Microsoft Excel. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted '.xls' file that, when loaded by the target user, will trigger a memory access error
and execute arbitrary code on the target system. The code will run with the privileges of the target user.
Microsoft Office
Excel 2007 is not affected.
Jie Ma of Fortinet Security Research Team discovered this vulnerability.
The original advisory
is available at:
http://www.fortinet.com/FortiGuardCenter/advisory/FG-2007-01.html
|
Impact: A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution: The vendor has issued the following fixes (which also fix other Excel vulnerabilities reported in Alert ID 1017487):
Microsoft
Excel 2000:
http://www.microsoft.com/downloads/details.aspx?familyid=5CCF4455-6B22-4249-93D7-661D12839292
Microsoft Excel
2002:
http://www.microsoft.com/downloads/details.aspx?FamilyId=EE7278EA-3AEE-4994-9657-66019961D63C
Microsoft Excel 2003:
http://www.microsoft.com/downloads/deta
ils.aspx?FamilyId=79B88CE8-5C56-462F-AC1A-4BCE04C8F543
Microsoft Office Excel Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=99AE7653-F0FD-4D
BA-A151-098FD03E6EA4
Microsoft Works Suite 2004:
http://www.microsoft.com/downloads/details.aspx?FamilyId=EE7278EA-3AEE-4994-9657-66019961D63C
Microsoft
Works Suite 2005:
http://www.microsoft.com/downloads/details.aspx?FamilyId=EE7278EA-3AEE-4994-9657-66019961D63C
Microsoft
Office 2004 for Mac:
http://www.microsoft.com/mac/
Microsoft Office v. X for Mac:
http://www.microsoft.com/mac/
The
Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms07-002.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms07-002.mspx (Links to External Site)
|
Cause: Access control error
|
Underlying OS: UNIX (OS X), Windows (2000), Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 9 Jan 2007 11:21:20 -0500
Subject: Critical Vulnerability Affecting Microsoft Excel (927198)
|
http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html
CVE-2006-3432
|
|