| Last Updated Date | May 01, 2009 |
| Release Date | Apr 17, 2009 |
| Severity | Critical |
| Impact | System Compromise: Remote attackers can gain control of vulnerable systems. |
| Description | This indicates an attack attempt to exploit a memory-corruption vulnerability in Microsoft Excel.
This vulnerability is caused by an error when the affected software handles a crafted XLS file with a malformed object. It allows a remote attacker to execute arbitrary code. |
| Affected Products | Microsoft Office Excel 2000 Service Pack 3 Microsoft Office Excel 2002 Service Pack 3 Microsoft Office Excel 2003 Service Pack 3 Microsoft Office Excel 2007 Service Pack 1 Microsoft Office 2004 for Mac Microsoft Office 2008 for Mac Microsoft Office Excel Viewer 2003 Service Pack 3 Microsoft Office Excel Viewer Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1 |
| Recommended Actions | Apply the patch, available from the vendor's website: http://www.microsoft.com/technet/security/Bulletin/ms09-009.mspx |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0100
|
| Microsoft Bulletin ID | MS09-009 http://www.microsoft.com/technet/security/Bulletin/ms09-009.mspx |