CVE-2010-1252: Code Injection
Published Jun 8, 2010
·Updated
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
Affected Software
2 affected components
Microsoft Excel=2002-sp3
Microsoft Office=2004
Event History
Jun 8, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1252?
CVE-2010-1252 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2010-1252?
To mitigate CVE-2010-1252, users should apply the latest security updates provided by Microsoft for the affected versions.
3
Which software is affected by CVE-2010-1252?
CVE-2010-1252 affects Microsoft Excel 2002 SP3 and Microsoft Office 2004 for Mac.
4
What type of attack does CVE-2010-1252 enable?
CVE-2010-1252 enables remote attackers to execute arbitrary code by exploiting a crafted Excel file.
5
Is there any workaround for CVE-2010-1252?
Users can protect themselves from CVE-2010-1252 by avoiding opening Excel files from untrusted sources until a patch is applied.