CVE-2010-3238: Input Validation
Published Oct 13, 2010
·Updated
Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."
Affected Software
3 affected components
Microsoft Office=2004
Microsoft Excel=2002-sp3
Microsoft Excel=2003-sp3
Event History
Oct 13, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3238?
CVE-2010-3238 is classified as a critical vulnerability that allows remote code execution.
2
How do I fix CVE-2010-3238?
To fix CVE-2010-3238, you should install the applicable security update provided by Microsoft.
3
What software is affected by CVE-2010-3238?
CVE-2010-3238 affects Microsoft Excel 2002 SP3, Microsoft Excel 2003 SP3, and Office 2004 for Mac.
4
Can CVE-2010-3238 be exploited remotely?
Yes, CVE-2010-3238 can be exploited remotely through a crafted Excel document.
5
What type of attack does CVE-2010-3238 enable?
CVE-2010-3238 enables an attacker to execute arbitrary code on the affected system.