First published: Tue Jan 09 2007(Updated: )
Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac | =2000 | |
Microsoft Office | =2000-sp3 | |
Microsoft Excel for Mac | =2002 | |
Microsoft Office | =xp-sp3 | |
Microsoft Excel for Mac | =2003 | |
Microsoft Office | =2003-sp2 | |
Microsoft Excel Viewer | =2003 | |
Microsoft Works | =2004 | |
Microsoft Works | =2005 | |
Microsoft Office | =2004 | |
Microsoft Office | =v.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0031 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2007-0031, users should apply the latest security patches provided by Microsoft for the affected versions of Excel and Office.
CVE-2007-0031 affects Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, Microsoft Office 2000 SP3, 2003 SP2, and various versions for Mac.
CVE-2007-0031 can be exploited by user-assisted remote attackers through malicious BIFF8 spreadsheets.
While CVE-2007-0031 may primarily affect older software versions, any systems that have not been updated remain at risk.