Thread-topic: [SA25995] Microsoft Excel Multiple Code Execution Vulnerabilities
> ----------------------------------------------------------------------
>
> TITLE:
> Microsoft Excel Multiple Code Execution Vulnerabilities
>
> SECUNIA ADVISORY ID:
> SA25995
>
> VERIFY ADVISORY:
>
>
> CRITICAL:
> Highly critical
>
> IMPACT:
> System access
>
> WHERE:
> From remote
>
> SOFTWARE:
> Microsoft Office Excel 2007
>
> Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint
> 2007 File Formats
>
> Microsoft Excel Viewer 2003
>
> Microsoft Excel 2003
>
> Microsoft Excel 2002
>
> Microsoft Excel 2000
>
> Microsoft Office 2000
>
> Microsoft Office XP
>
> Microsoft Office 2003 Professional Edition
>
> Microsoft Office 2003 Small Business Edition
>
> Microsoft Office 2003 Standard Edition
>
> Microsoft Office 2003 Student and Teacher Edition
>
> Microsoft Office 2007
>
>
> DESCRIPTION:
> Some vulnerabilities have been reported in Microsoft Excel, which can
> be exploited by malicious people to compromise a user's system.
>
> 1) An unspecified calculation error when handling version-related
> information can be exploited to corrupt memory via a specially
> crafted Excel file.
>
> 2) An error in the validation of the number of active worksheets can
> be exploited to corrupt memory via a specially crafted Excel file.
>
> 3) An error when validating the beginning of file attributes
> associated with workspace information can be exploited via a
> specially crafted Excel file.
>
> Successful exploitation of the vulnerabilities may allow execution of
> arbitrary code.
>
> NOTE: Additional unspecified security issues discovered internally by
> Microsoft have also been reported.
>
> SOLUTION:
> Apply patches.
>
> Microsoft Excel 2000 SP3:
>
> D8E-DDA6-4D74-B40D-476C2F0A3AF4
>
> Microsoft Excel 2002 SP3:
>
> 13B-D4B0-48FD-9880-73C180570267
>
> Microsoft Excel 2003 SP2:
>
> 0CE-5124-4234-BA84-3C27005E010F
>
> Microsoft Excel 2003 Viewer:
>
> 977-8828-494A-A183-D1ABA827B708
>
> Microsoft Office Excel 2007:
>
> 283-0320-4527-B033-5E80EF32CD34
>
> Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint
> 2007 File Formats:
>
> E5B-09AC-4F5B-B457-A54C9850AD4A
>
> PROVIDED AND/OR DISCOVERED BY:
> Reported by the vendor.
>
> ORIGINAL ADVISORY:
> MS07-036 (KB936542):
>
>