MS.Office.Excel.SXDB.Record.Type.Code

NameMS.Office.Excel.SXDB.Record.Type.Code.Execution
Last Updated DateJan 12, 2010
Release DateNov 12, 2009
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a remote code execution vulnerability in Microsoft Office Excel.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted Excel file. It allows a remote attacker to execute arbitrary code.
Affected ProductsMicrosoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 3
Microsoft Office Excel 2007 Service Pack 1
Microsoft Office Excel 2007 Service Pack 2
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Microsoft Office Excel Viewer 2003 Service Pack 3
Microsoft Office Excel Viewer Service Pack 1
Microsoft Office Excel Viewer Service Pack 2
Recommended ActionsApply patch, available from the web site:

http://www.microsoft.com/technet/security/Bulletin/MS09-067.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3127
Microsoft Bulletin IDMS09-067   http://www.microsoft.com/technet/security/Bulletin/MS09-067.mspx
Reference/shttp://www.securityfocus.com/bid/36943 (BugTraq)
Reference: VID-17920