CVE-2011-0979
Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a malformed object record, related to a "stray reference," aka "Excel Linked List Corruption Vulnerability."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 26.52% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/excel · microsoft/excel viewer · microsoft/office · microsoft/office compatibility pack · microsoft/open xml file format converter
- Source
- cve@mitre.org
References
- http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsoft
- http://osvdb.org/70904
- http://secunia.com/advisories/39122Vendor Advisory
- http://secunia.com/advisories/43231Vendor Advisory
- http://www.securitytracker.com/id?1025337
- http://www.us-cert.gov/cas/techalerts/TA11-102A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2011/0940Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-11-041/
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-021
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12595
- http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsoft
- http://osvdb.org/70904
- http://secunia.com/advisories/39122Vendor Advisory
- http://secunia.com/advisories/43231Vendor Advisory
- http://www.securitytracker.com/id?1025337
- http://www.us-cert.gov/cas/techalerts/TA11-102A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2011/0940Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-11-041/
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-021
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12595
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.