First published: Thu Sep 15 2011(Updated: )
Microsoft Excel 2007 SP2; Excel in Office 2007 SP2; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Excel Services on Office SharePoint Server 2007 SP2 do not properly validate the sign of an unspecified array index, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Out of Bounds Array Indexing Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp2 | |
Microsoft Office Excel Viewer | =sp2 | |
Microsoft Office | =2007-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =2007-sp2 | |
Microsoft SharePoint Server 2010 | =2007-sp2 | |
Microsoft SharePoint Server 2010 | =2007-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1990 has a medium severity rating, indicating potential for exploitation.
To fix CVE-2011-1990, users should install the security update provided by Microsoft.
CVE-2011-1990 affects Microsoft Excel 2007 SP2, Excel Viewer SP2, and various Office 2007 applications.
Yes, CVE-2011-1990 allows remote attackers to exploit the vulnerability via specially crafted files.
CVE-2011-1990 is a validation vulnerability associated with improper array index handling.