This application requires Javascript for optimal performance.

MS.Excel.DBQueryExt.Record.Memory.Corruption

Release Date

Jun 09, 2010

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a memory-corruption vulnerability in Microsoft Office Excel.

The vulnerability is caused by improper bounds checking when the vulnerable software handles an Excel file containing a malformed DBQueryExt record. It could allow a remote attacker to execute arbitrary code and take complete control of an affected system.

Affected Products

Excel 2000
Excel 2002
Excel 2007

Recommended Actions

Apply the patch supplied by the vendor:
http://www.microsoft.com/technet/security/Bulletin/MS10-038.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-1253

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS10-038.mspx (MS-ID)
http://www.securityfocus.com/bid/40531 (BugTraq)

Reference: VID-23337