Summary
This host is missing a critical security update according to Microsoft Bulletin MS09-067.
Impact
Successful exploitation could execute arbitrary code on the remote system and corrupt memory, buffer overflow via a specially crafted Excel file.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/MS09-067
Insight
- An error in the parsing of Excel spreadsheets can be exploited to corrupt memory via a specially crafted Excel file.
- An error in the processing of certain record objects can be exploited to corrupt memory via a specially crafted Excel file.
- Another error in the processing of certain record objects can be exploited to corrupt memory via a specially crafted Excel file.
- An error in the processing of Binary File Format (BIFF) records can be exploited to cause a heap-based buffer overflow via a specially crafted Excel file.
- An error in the handling of formulas embedded inside a cell can be exploited to corrupt memory via a specially crafted Excel file.
- An error when loading Excel formulas can be exploited to corrupt a pointer when a specially crafted Excel file is being opened.
- An error when loading Excel records can be exploited to corrupt memory via a specially crafted Excel file.
- An error when processing Excel record objects can be exploited via a specially crafted Excel file.
Affected
Microsoft Excel Viewer 2003/2007
Microsoft Office Excel 2002/2003/2007
Microsoft Office Compatibility Pack for Word,Excel,PowerPoint 2007 File Formats SP 1/2
References
Severity
Classification
-
CVE CVE-2009-3127, CVE-2009-3128, CVE-2009-3129, CVE-2009-3130, CVE-2009-3131, CVE-2009-3132, CVE-2009-3133, CVE-2009-3134 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft IIS FTP Server 'Malformed FTP List Request' DOS Vulnerability
- Microsoft DirectShow Remote Code Execution Vulnerability (2845187)
- Microsoft Internet Explorer Multiple Memory Corruption Vulnerabilities (2870699)
- Microsoft IIS Authentication Remote Code Execution Vulnerability (982666)
- Microsoft GDI+ Remote Code Execution Vulnerability (2489979)