First published: Wed Mar 10 2010(Updated: )
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that causes memory to be interpreted as a different object type than intended, aka "Microsoft Office Excel Sheet Object Type Confusion Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2002-sp3 | |
Microsoft Office Excel | =2003-sp3 | |
Microsoft Office Excel | =2007-sp1 | |
Microsoft Office Excel | =2007-sp2 | |
Microsoft Office for Mac OS X | =2004 | |
Microsoft Office | =2008 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =2007-sp1 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =2007-sp2 | |
Microsoft Office Viewer | =sp1 | |
Microsoft Office Viewer | =sp2 | |
Microsoft SharePoint Portal Server | =2007-sp1 | |
Microsoft SharePoint Portal Server | =2007-sp2 | |
Microsoft Open XML File Format Converter | ||
Microsoft Office | =2004 | |
Microsoft Office | =2008 | |
Microsoft Office Viewer | =sp1 | |
Microsoft Office Viewer | =sp2 | |
Microsoft SharePoint Portal Server | =2007-sp1 | |
Microsoft SharePoint Portal Server | =2007-sp1 | |
Microsoft SharePoint Portal Server | =2007-sp2 | |
Microsoft SharePoint Portal Server | =2007-sp2 | |
Microsoft Open XML File Format Converter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0258 has been classified with a critical severity level due to the potential for arbitrary code execution.
To fix CVE-2010-0258, users should update their Microsoft Excel and related software to the latest available service packs or versions.
CVE-2010-0258 affects multiple versions of Microsoft Excel including 2002, 2003, and 2007, as well as Office for Mac and other related Microsoft software.
CVE-2010-0258 is a vulnerability related to improper parsing of Excel files, which may allow for code execution.
Individuals and organizations using the affected versions of Microsoft Excel or related software are at risk from CVE-2010-0258.