CVE-2010-0264: Code Injection
Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0264?
CVE-2010-0264 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2010-0264?
To fix CVE-2010-0264, users should install the latest security updates provided by Microsoft for affected versions of Excel and Office.
Which software is affected by CVE-2010-0264?
CVE-2010-0264 affects Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2, as well as Microsoft Office 2004 and 2008 for Mac.
What type of attack is possible with CVE-2010-0264?
CVE-2010-0264 could allow remote attackers to execute arbitrary code by exploiting a vulnerability in the parsing of crafted spreadsheet files.
Is there a workaround for CVE-2010-0264?
While the best solution is to apply the patch, users may limit exposure by avoiding opening untrusted Excel files.