CVE-2007-1239: Null Pointer Dereference
Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1239?
CVE-2007-1239 has been classified as a denial of service vulnerability which can cause application crashes in Microsoft Excel 2003.
How do I fix CVE-2007-1239?
To fix CVE-2007-1239, ensure you have the latest updates or patches for Microsoft Excel 2003 installed, specifically for service pack updates.
What versions of Microsoft Excel are affected by CVE-2007-1239?
CVE-2007-1239 affects Microsoft Excel 2003, including both Service Pack 1 and Service Pack 2 versions.
Can CVE-2007-1239 be exploited remotely?
Yes, CVE-2007-1239 can be exploited remotely by sending a specially crafted .XLS file to the user.
What symptoms indicate an attack leveraging CVE-2007-1239?
Symptoms of an attack leveraging CVE-2007-1239 may include unexpected application crashes when opening specific .XLS files.