Microsoft Excel Formula, Object, and Global Array Bugs Let Remote Users Execute Arbitrary Code
|
SecurityTracker Alert ID: 1021368 |
SecurityTracker URL: http://securitytracker.com/id/1021368
|
CVE Reference:
CVE-2008-4264, CVE-2008-4265, CVE-2008-4266
(Links to External Site)
|
Updated: Jan 29 2009
|
Original Entry Date: Dec 9 2008
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
Three vulnerabilities were reported in Microsoft Excel. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create an Excel file with a specially crafted formula that, when loaded by the target user, will trigger a pointer corruption error and execute arbitrary code on the target system [CVE-2008-4264]. The code will run with the privileges of the target user.
A remote user can create a specially crafted Excel file that, when loaded by the target user, will trigger a memory corruption error and execute arbitrary code on the target system [CVE-2008-4265]. The code will run with the privileges of the target user.
A remote user can create a specially crafted Excel file that, when loaded by the target user, will trigger a stack corruption error and execute arbitrary code on the target system [CVE-2008-4266]. The code will run with the privileges of the target user.
Joshua J. Drake of VeriSign iDefense Labs, Claes M Nyberg of signedness.org, and Dyon Balding of Secunia reported these vulnerabilities.
|
Impact:
A remote user can create an Excel file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
The vendor has issued the following fixes:
Microsoft Office Excel 2000 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=f39d2a49-f861-4f2d-bf91-94a8a85af40c
Microsoft Office Excel 2002 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=72076e21-2aa3-48e8-883a-c3cb756fc72a
Microsoft Office Excel 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=6c0771e5-fcd4-4365-b903-1a3bd95d9e66
Microsoft Office Excel 2007:
http://www.microsoft.com/downloads/details.aspx?familyid=68bb8d99-f28b-4efd-9314-3eee0bb00ccf
Microsoft Office Excel 2007 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=68bb8d99-f28b-4efd-9314-3eee0bb00ccf
For Office Excel 2007 and 2007 SP1, the security update KB958439 for Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats is also required.
Microsoft Office Excel Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?familyid=4b3989ef-02b8-4bd2-b2ab-c3716079936e
Microsoft Office Excel Viewer 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=4b3989ef-02b8-4bd2-b2ab-c3716079936e
Microsoft Office Excel Viewer:
http://www.microsoft.com/downloads/details.aspx?familyid=9dbb35c1-aa7a-481b-a330-8ba916ddd443
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats:
http://www.microsoft.com/downloads/details.aspx?familyid=99cca4ed-f1f9-4cfd-a986-edbec82ced4f
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=99cca4ed-f1f9-4cfd-a986-edbec82ced4f
Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?familyid=ECA13AD8-62AE-41A8-B308-41E2D1773820
Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/details.aspx?familyid=AB31A564-43D2-45BD-98BF-19E9CA477B62
Open XML File Format Converter for Mac:
http://www.microsoft.com/downloads/details.aspx?familyid=EDB6CD8F-832C-4123-8982-AC0C601EA0A7
The vendor's advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-074.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-074.mspx (Links to External Site)
|
Cause:
Access control error, Boundary error
|
Underlying OS: UNIX (macOS/OS X), Windows (2000), Windows (2003), Windows (2008), Windows (Vista), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|