Microsoft Excel Input Validation Bug in Processing Style Record Data Lets Remote Users Execute Arbitrary Code
|
SecurityTracker Alert ID: 1019584 |
SecurityTracker URL: http://securitytracker.com/id/1019584
|
CVE Reference:
CVE-2008-0114
(Links to External Site)
|
Updated: Mar 20 2008
|
Original Entry Date: Mar 11 2008
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2000 SP3, 2002 SP3, 2003 SP2, 2007; Excel Viewer 2003; Office 2004 for Mac; Office 2008 for Mac
|
Description:
A vulnerability was reported in Microsoft Excel in the processing of style record data. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create an Excel file with specially crafted style record information that, when loaded by the target user, will trigger a memory error and execute arbitrary code on the target user's system. The code will run with the privileges of the target user.
Bing Liu of Fortinet reported this vulnerability.
|
Impact:
A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
The vendor has issued the following fixes:
Microsoft Office 2000 Service Pack 3, Excel 2000 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=f7f90c30-1bfd-406b-a77f-612443e30185
Microsoft Office XP Service Pack 3, Excel 2002 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=907f96d5-d1e9-4471-b41c-3ac811e63038
Microsoft Office 2003 Service Pack 2, Excel 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=296e5f2c-f594-41c8-a20a-3e4c40ae3948
2007 Microsoft Office System, Excel 2007:
http://www.microsoft.com/downloads/details.aspx?FamilyId=e7634cb5-9531-4284-9554-4168fc488e0c
Microsoft Office Excel Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=280bb2ac-b21a-46b5-8751-5a50fbebf107
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats:
http://www.microsoft.com/downloads/details.aspx?FamilyId=e9251d71-9098-4125-ae91-7d4c83ea58ad
Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyId=95DCEB37-B35F-46DB-B280-DB0F3B298AA9
Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyId=8FE8C32A-6D7A-482B-97C6-42562F089EE4
A restart is not required.
On March 19, 2008, Microsoft re-released MS08-014 for Microsoft Office Excel 2003 SP2 and SP3 only to correct a calculation error that had no security impact. Instructions regarding the re-issue are available at:
http://support.microsoft.com/kb/950340
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-014.mspx (Links to External Site)
|
Cause:
Input validation error
|
Underlying OS: UNIX (macOS/OS X), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|