CVE-1999-1055: High severity Microsoft Excel vulnerability
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Office Excel 97from your environment.Uninstall or remove Microsoft Excel 97 from systems and stop using it, as Excel 97 is vulnerable to arbitrary code execution via the CALL worksheet function.
- Compensating control
Do not open Excel worksheets from untrusted sources. Isolate any systems that must run Excel 97 (run in a sandbox/VM, restrict network access and apply host-based access controls) to reduce exposure to exploitation via malicious CALL function payloads.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1055?
CVE-1999-1055 is considered a critical vulnerability due to its ability to execute arbitrary commands through malicious DLLs.
How do I fix CVE-1999-1055?
To fix CVE-1999-1055, apply the latest security updates provided by Microsoft for Excel 97.
What systems are affected by CVE-1999-1055?
CVE-1999-1055 specifically affects Microsoft Excel 97, including its versions for Mac.
What are the potential risks associated with CVE-1999-1055?
The risks of CVE-1999-1055 include the possibility of unauthorized command execution, leading to data breaches or system compromise.
Is there a workaround for CVE-1999-1055?
A suggested workaround for CVE-1999-1055 is to avoid executing untrusted worksheets that may utilize the CALL function.