CVE-2008-3004: Input Validation
Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3; Office Excel Viewer 2003; and Office 2004 and 2008 for Mac do not properly validate index values for AxesSet records when loading Excel files, which allows remote attackers to execute arbitrary code via a crafted Excel file, aka the "Excel Indexing Validation Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3004?
CVE-2008-3004 is classified as critical due to its potential to allow remote code execution.
How do I fix CVE-2008-3004?
To fix CVE-2008-3004, update to the latest security patches provided by Microsoft for affected versions of Office Excel.
Which versions are affected by CVE-2008-3004?
CVE-2008-3004 affects Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, Office Excel Viewer 2003, and Office 2004 and 2008 for Mac.
What kind of attacks are possible with CVE-2008-3004?
CVE-2008-3004 allows attackers to execute arbitrary code on the victim's system via a crafted Excel file.
How can I determine if my system is vulnerable to CVE-2008-3004?
You can determine your vulnerability to CVE-2008-3004 by checking the version of Microsoft Office applications installed on your system.