CVE-2010-3240: Input Validation
Microsoft Excel 2002 SP3 and 2007 SP2; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Real Time Data Array Record Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3240?
CVE-2010-3240 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2010-3240?
To fix CVE-2010-3240, apply the relevant security update provided by Microsoft for affected Excel versions.
Which software versions are affected by CVE-2010-3240?
CVE-2010-3240 affects Microsoft Excel 2002 SP3, Excel 2007 SP2, Excel Viewer SP2, and the Office Compatibility Pack for Word, Excel, and PowerPoint 2007 SP2.
What types of attacks are possible with CVE-2010-3240?
CVE-2010-3240 allows remote attackers to execute arbitrary code through a specially crafted Excel document.
Are there any mitigation strategies for CVE-2010-3240?
Mitigation strategies for CVE-2010-3240 include avoiding the opening of untrusted or unknown Excel files.