Microsoft Office 2000
SP3
Microsoft Office XP SP3
Microsoft Office 2003 SP2
Microsoft Office 2003 SP3
Microsoft Office System 2007
Microsoft Office System 2007 SP1
Microsoft Office Excel Viewer 2003
Microsoft Office Excel Viewer 2003 SP3
Microsoft Office Excel Viewer
Microsoft Office SharePoint Server 2007
Microsoft Office SharePoint Server 2007 SP1
Microsoft Office SharePoint Server 2007 x64
Microsoft Office SharePoint
Server 2007 x64 SP1
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Synopsis
Microsoft Excel
is prone to a record parsing vulnerability. This vulnerability exists
in the way Excel parses record values when loading Excel files into
memory. Depending on the attack scenario, the vulnerability could lead
to remote code execution on a user's local Excel client, or it could
lead to elevation of privilege within a SharePoint Server.
Microsoft
Excel does not perform sufficient validation when parsing record values
when loading Excel files into memory. An attacker could exploit the
vulnerability by convincing a user to open a specially crafted file
which could be hosted on a Web site, or included as an e-mail
attachment.
An attacker who successfully exploited this vulnerability could take
complete control of an affected system. An attacker could then install
programs, view, change, delete data or create new accounts with full
user rights.
“iPolicy is one of the most visionary firewall vendors in the firewall Magic Quadrant. Its architecture of a central session processing engine and multiple content blades that are able to block based on signatures, rules and so on is the closest to the network security ideal.”
Greg Young, John Pescatore
Magic Quadrant for Network Firewalls, 2H04, Gartner