First published: Wed Nov 11 2009(Updated: )
Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Open XML File Format Converter | ||
Microsoft Office | =2008 | |
Microsoft Office | =2004 | |
Microsoft Excel for Mac | =2007-sp2 | |
Microsoft Excel Viewer | =sp2 | |
Microsoft Excel for Mac | =2007-sp1 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =2007-sp2 | |
Microsoft Excel Viewer | =2003-sp3 | |
Microsoft Excel for Mac | =2002-sp3 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =2007-sp1 | |
Microsoft Excel for Mac | =2003-sp3 | |
Microsoft Excel Viewer | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3128 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
To fix CVE-2009-3128, you should apply the latest updates and patches provided by Microsoft for affected versions of Excel.
CVE-2009-3128 affects Microsoft Office Excel 2002 SP3, 2003 SP3, Excel Viewer 2003 SP3, and other related software.
Yes, CVE-2009-3128 can be exploited through specially crafted Excel files sent via email attachments.
If not addressed, CVE-2009-3128 could allow an attacker to run malicious code on the affected system, potentially leading to data loss or unauthorized access.