CVE-2007-0215: Buffer Overflow
Published May 8, 2007
·Updated
Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
Affected Software
10 affected components
Microsoft Office=2004
Microsoft Excel=2000
Microsoft Office=xp-sp3
Microsoft Office=2003-sp2
Microsoft Excel Viewer=2003
Microsoft Excel=2002
Microsoft Excel=2007
Microsoft Excel=2003
Microsoft Office=2007
Microsoft Office=2000-sp3
Remediation
Patch Available
Event History
May 8, 2007
CVE Published
10:19 PM
May 9, 2007
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0215?
CVE-2007-0215 is rated as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2007-0215?
To mitigate CVE-2007-0215, apply the latest patches provided by Microsoft for affected versions of Excel.
3
Which versions of Microsoft Excel are affected by CVE-2007-0215?
CVE-2007-0215 affects Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and the 2003 Viewer.
4
What type of vulnerability is CVE-2007-0215?
CVE-2007-0215 is a stack-based buffer overflow vulnerability.
5
Can CVE-2007-0215 be exploited remotely?
Yes, CVE-2007-0215 can be exploited by remote attackers through the use of specially crafted .XLS files.