| Name | MS.Office.Excel.XLSX.File.Parsing.Code.Execution |
| Last Updated Date | Apr 22, 2010 |
| Release Date | Mar 10, 2010 |
| Severity | Critical |
| Impact | System Compromise: Remote attackers can gain control of vulnerable systems. |
| Description | This indicates an attack attempt against a memory corruption vulnerability in Microsoft Office Excel.
The vulnerability is caused by an error when the vulnerable software is parsing a malformed ".xlsx" file. It may allow remote attackers to execute arbitrary code by sending a crafted XLSX file. |
| Affected Products | Microsoft Office Excel 2007 Service Pack 1 and Microsoft Office Excel 2007 Service Pack 2 Microsoft Office 2008 for Mac Open XML File Format Converter for Mac Microsoft Office Excel Viewer Service Pack 1 and Microsoft Office Excel Viewer Service Pack 2 Microsoft Office Compatibility Pack for Word, Excel, an Microsoft Office SharePoint Server 2007 Service Pack 1 (32-bit editions) and Microsoft Office SharePoint Server 2007 Service Pack 2 (32-bit editions) Microsoft Office SharePoint Server 2007 Service Pack 1 (64-bit editions) and Microsoft Office SharePoint Server 2007 Service Pack 2 (64-bit editions) |
| Recommended Actions | Refer to the vendor's web site for suggested workaround. http://www.microsoft.com/technet/security/Bulletin/ms10-017.mspx |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0263
|
| Microsoft Bulletin ID | MS10-017 http://www.microsoft.com/technet/security/Bulletin/ms10-017.mspx |