Check Point Reference: | SBP-2010-27 |
Date Published: | 12 Oct 2010 |
Severity: | High |
Last Updated: | Friday 03 December, 2010 |
Source: | Microsoft Security Bulletin MS10-080 |
Industry Reference: | CVE-2010-3230 |
Protection Provided by: | |
Who is Vulnerable? | Microsoft Excel 2002 SP3 |
Vulnerability Description | A memory corruption vulnerability has been identified in Microsoft Excel. Microsoft Excel is a popular spreadsheet application. A remote attacker could exploit this issue via a malformed Excel file. Successful exploitation of this vulnerability may allow execution of arbitrary code on a target system. |
Update/Patch Avaliable | Apply patches: Microsoft Security Bulletin MS10-080 |
Vulnerability Details | The vulnerability is due to an error in Microsoft Office Excel that fails to properly validate record information upon opening a specially crafted Excel file. A remote attacker could trigger this flaw by convincing a victim to open a specially crafted Excel file that includes a malformed CrErr BIFF record. Successful exploitation of this issue may allow execution of arbitrary code on a vulnerable system. |