CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS07-036 | Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (936542) | Microsoft Office | Critical | 11-07-2007 |
Technical Information
Brief overview of the risk:
An attacker who successfully exploits this vulnerability could run arbitrary code on the affected system as the logged on user.
Detailed Information on the risk:
A remote code execution vulnerability exists in the way Excel handles malformed Excel files. An attacker could exploit the vulnerability by sending a malformed file which could be included as an e-mail attachment, or hosted on a malicious or compromised Web site.
This critical update resolves one publicly disclosed vulnerability and two privately reported vulnerabilities.Further information on this exploit is available at : MS07-036
Affected Software
Microsoft Office 2000 Service Pack 3( Microsoft Excel 2000 Service Pack 3 )Microsoft Office XP Service Pack 3( Microsoft Excel 2002 Service Pack 3 )
Microsoft Office 2003 Service Pack 2( Microsoft Excel 2003 Service Pack 2 )
Microsoft Excel 2003 Viewer
2007 Microsoft Office System ( Microsoft Office Excel 2007 )
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats