First published: Thu Jun 16 2011(Updated: )
Microsoft Excel 2002 SP3; Office 2004, 2008, and 2011 for Mac; and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Heap Overwrite Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2002-sp3 | |
Microsoft Office | =2004 | |
Microsoft Office | =2008 | |
Microsoft Office | =2011 | |
Microsoft Open XML File Format Converter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1275 is rated as critical due to its potential for remote code execution.
The vulnerability can be addressed by applying the security updates provided by Microsoft for affected Office versions.
CVE-2011-1275 affects Microsoft Excel 2002 SP3, Office 2004, 2008, 2011 for Mac, and Open XML File Format Converter for Mac.
CVE-2011-1275 allows attackers to execute arbitrary code or cause a denial of service due to memory corruption.
Disabling the use of vulnerable Excel file formats can serve as a temporary workaround until an update is applied.