First published: Tue Aug 14 2007(Updated: )
Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac | =2000-sp3 | |
Microsoft Excel for Mac | =2003-sp2 | |
Microsoft Excel for Mac | =2004 | |
Microsoft Excel for Mac | =xp_sp3 | |
Microsoft Office | =2000-sp3 | |
Microsoft Office | =2003-sp2 | |
Microsoft Office | =2004 | |
Microsoft Office | =xp-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3890 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2007-3890, it is recommended to apply the latest security updates from Microsoft for the affected Office versions.
CVE-2007-3890 affects Microsoft Excel 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac.
CVE-2007-3890 allows remote attackers to execute arbitrary code via a crafted Workspace file.
As a temporary workaround for CVE-2007-3890, users should avoid opening untrusted Excel files or limit Excel's access to the network.