MS.Excel.Index.Value.Memory.Corruption

Release DateDec 12, 2008
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attempt to exploit a function pointer override vulnerability in Microsoft Excel products, which is due to insufficient validation of an index value in the NAME record.
Affected ProductsMicrosoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 3
2007 Microsoft Office System and its Service Pack 1
Microsoft Office Excel Viewer 2003 and its Service Pack 3
Microsoft Office Excel Viewer
Microsoft Office for Mac
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Open XML File Format Converter for Mac
Recommended ActionsApply the patch, available from the vendor's web site:
http://www.microsoft.com/technet/security/Bulletin/ms08-074.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4266
Microsoft Bulletin IDMS08-074   http://www.microsoft.com/technet/security/Bulletin/ms08-074.mspx
Reference: VID-16751