MS.Excel.Missing.MSO.Drawing.Group

NameMS.Excel.Missing.MSO.Drawing.Group.Stack.Overrun
Last Updated DateFeb 19, 2009
Release DateDec 12, 2008
SeverityCritical
ImpactSystem compromise
DescriptionThis indicates a possible attempt to exploit a stack-overrun vulnerability in Microsoft Office Excel.

This vulnerability is caused by the software's inability to properly parse a malformed XLS file. Remote users may exploit this to execute arbitrary code.
Affected ProductsMicrosoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 3
2007 Microsoft Office System and its Service Pack 1
Microsoft Office Excel Viewer 2003 and its Service Pack 3
Microsoft Office Excel Viewer
Microsoft Office for Mac
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Open XML File Format Converter for Mac
Recommended ActionsApply the patch, available from the vendor's web site:
http://www.microsoft.com/technet/security/Bulletin/ms08-074.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4265
Microsoft Bulletin IDMS08-074   http://www.microsoft.com/technet/security/Bulletin/ms08-074.mspx
Reference/shttp://www.securityfocus.com/bid/32618 (BugTraq)
Reference: VID-16744