CVE-2011-1986: Use After Free
Published Sep 15, 2011
·Updated
Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
Affected Software
1 affected component
Microsoft Excel=2003-sp3
Event History
Sep 15, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1986?
CVE-2011-1986 is considered critical due to its potential to allow remote code execution.
2
How do I fix CVE-2011-1986?
To fix CVE-2011-1986, apply the security update provided by Microsoft for Excel 2003 SP3.
3
Which versions of Microsoft Excel are affected by CVE-2011-1986?
CVE-2011-1986 specifically affects Microsoft Excel 2003 SP3.
4
What type of attacks can exploit CVE-2011-1986?
CVE-2011-1986 can be exploited through crafted spreadsheets that trigger the use-after-free vulnerability.
5
Is there a workaround for CVE-2011-1986 if I cannot apply the update?
A temporary workaround for CVE-2011-1986 is to limit the ability to open untrusted Excel files until the update is applied.