First published: Wed Jun 10 2009(Updated: )
Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Open XML File Format Converter | ||
Microsoft Office | =2008 | |
Microsoft Office Excel | =2007-sp2 | |
Microsoft SharePoint Portal Server | =2007-sp1 | |
Microsoft Office | =2004 | |
Microsoft Office | =xp-sp3 | |
Microsoft Office Viewer | ||
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp1 | |
Microsoft Office Viewer | =2003-sp3 | |
Microsoft SharePoint Portal Server | =2007-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp2 | |
Microsoft Office Excel | =2003-sp3 | |
Microsoft SharePoint Portal Server | =2007-sp1 | |
Microsoft Office Excel | =2000-sp3 | |
Microsoft SharePoint Portal Server | =2007-sp2 | |
Microsoft Office Excel | =2007-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0558 has been rated with a critical severity level due to its potential for remote code execution.
To fix CVE-2009-0558, apply the latest security updates provided by Microsoft for the affected Office versions.
CVE-2009-0558 affects Microsoft Office 2000 SP3, Office 2004, 2008 for Mac, and various versions of Microsoft Office Excel and Compatibility Packs.
Yes, CVE-2009-0558 can be exploited remotely through specially crafted Excel files leveraging a malformed record object.
Exploitation of CVE-2009-0558 can lead to arbitrary code execution on the vulnerable system.