CVE-2010-0263: Code Injection
Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Office SharePoint Server 2007 SP1 and SP2 do not validate ZIP headers during decompression of Open XML (.XLSX) documents, which allows remote attackers to execute arbitrary code via a crafted document that triggers access to uninitialized memory locations, aka "Microsoft Office Excel XLSX File Parsing Code Execution Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0263?
CVE-2010-0263 has been classified as a medium severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2010-0263?
To fix CVE-2010-0263, ensure that you have applied the latest security updates for Microsoft Office products as recommended by Microsoft.
Which software is affected by CVE-2010-0263?
CVE-2010-0263 affects Microsoft Office Excel 2007 SP1 and SP2, Office 2008 for Mac, and other related Microsoft Office products.
What kind of vulnerability is CVE-2010-0263?
CVE-2010-0263 is a vulnerability that involves improper validation of ZIP file headers, potentially allowing arbitrary code execution.
Can CVE-2010-0263 be exploited by an attacker?
Yes, CVE-2010-0263 can potentially be exploited by an attacker through maliciously crafted Excel documents.