CVE-2007-0028: Input Validation
Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0028?
CVE-2007-0028 is classified as an Improper Memory Access Vulnerability, which can allow an attacker to execute arbitrary code.
How do I fix CVE-2007-0028?
To mitigate CVE-2007-0028, users should update to the latest versions of Microsoft Excel and Office that address this vulnerability.
What versions of Microsoft software are affected by CVE-2007-0028?
CVE-2007-0028 affects Microsoft Excel 2000, 2002, 2003, Excel Viewer 2003, Office 2004 for Mac, and Office v.X for Mac.
How can an attacker exploit CVE-2007-0028?
An attacker can exploit CVE-2007-0028 by persuading a user to open a crafted XLS file, leading to arbitrary code execution.
Is user action required for CVE-2007-0028 to be exploited?
Yes, CVE-2007-0028 requires user-assisted action, specifically the opening of a malicious XLS file.