First published: Thu Jun 16 2011(Updated: )
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds WriteAV Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Open XML File Format Converter | ||
Microsoft Office | =2008 | |
Microsoft Office | =2004 | |
Microsoft Office Excel | =2002-sp3 | |
Microsoft Office Excel | =2003-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1279 has a medium severity rating due to the potential for remote code execution and denial of service attacks.
To fix CVE-2011-1279, users should apply the latest security updates and patches provided by Microsoft for the affected versions of Excel and Office.
CVE-2011-1279 affects Microsoft Excel 2002 SP3, 2003 SP3, Office 2004 and 2008 for Mac, and the Open XML File Format Converter for Mac.
The risks associated with CVE-2011-1279 include potential arbitrary code execution and memory corruption leading to denial of service.
There are no official workarounds for CVE-2011-1279; users are advised to update affected software to mitigate the risk.