First published: Tue Mar 11 2008(Updated: )
Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft compatibility pack word Excel powerpoint 2007 | ||
Microsoft Excel for Mac | =2000-sp3 | |
Microsoft Excel for Mac | =2002-sp3 | |
Microsoft Excel for Mac | =2003-sp2 | |
Microsoft Excel for Mac | =2007 | |
Microsoft Excel Viewer | =2003 | |
Microsoft Office | =2000-sp3 | |
Microsoft Office | =2003-sp2 | |
Microsoft Office | =2004 | |
Microsoft Office | =2007 | |
Microsoft Office | =2008 | |
Microsoft Office | =xp-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0117 has a moderate severity rating due to the potential for arbitrary code execution.
To fix CVE-2008-0117, users should apply the latest patches and updates provided by Microsoft for affected versions.
CVE-2008-0117 affects Microsoft Excel 2000 SP3, 2002 SP2, 2003 SP2, 2007, as well as Office 2000 SP3, 2003 SP2, 2004, 2007, and 2008 for Mac.
CVE-2008-0117 allows remote attackers to execute arbitrary code through specially crafted conditional formatting values.
Yes, user interaction is required as the vulnerability can be exploited through manipulated Excel files that need to be opened by the victim.