<< Back
CVE Number Vulnerability Product Severity Date
MS07-036 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (936542) Microsoft Office Critical 11-07-2007

Technical Information

Brief overview of the risk:
An attacker who successfully exploits this vulnerability could run arbitrary code on the affected system as the logged on user.
Detailed Information on the risk:
A remote code execution vulnerability exists in the way Excel handles malformed Excel files. An attacker could exploit the vulnerability by sending a malformed file which could be included as an e-mail attachment, or hosted on a malicious or compromised Web site.
This critical update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities.Further information on this exploit is available at : MS07-036

Affected Software

Microsoft Office 2000 Service Pack 3( Microsoft Excel 2000 Service Pack 3 )
Microsoft Office XP Service Pack 3( Microsoft Excel 2002 Service Pack 3 )
Microsoft Office 2003 Service Pack 2( Microsoft Excel 2003 Service Pack 2 )
Microsoft Excel 2003 Viewer
2007 Microsoft Office System ( Microsoft Office Excel 2007 )
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats