First published: Wed May 09 2012(Updated: )
Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp2 | |
Microsoft Office Excel | =2007-sp3 | |
Microsoft Office Excel | =2010 | |
Microsoft Office Excel | =2010-sp1 | |
Microsoft Office Excel Viewer | ||
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0185 is rated as critical due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2012-0185, ensure that you apply the latest security updates and patches provided by Microsoft.
CVE-2012-0185 affects Microsoft Excel 2007 SP2 and SP3, Excel 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3.
Yes, CVE-2012-0185 can be exploited remotely through a crafted spreadsheet that a user opens.
Exploiting CVE-2012-0185 can lead to unauthorized remote code execution, potentially compromising system security.