MS.Excel.ContinueFrt12.Record.Parsing.Heap.Buffer.Overflow

description-logoDescription

This indicates an attack attempt to exploit a Buffer Overflow Vulnerability in Microsoft Office.
The vulnerability is due to improper validation on user-supplied data while parsing ContinueFrt12 records in an XLS document. A remote attacker can exploit this vulnerability by enticing a user to open a specially crafted XLS document. Successful exploitation could result in arbitrary code execution in the context of the currently logged on user

affected-products-logoAffected Products

Microsoft Excel 2013
Microsoft Excel 2016
Microsoft Office 2019
Microsoft 365 Apps for Enterprise
Microsoft Office Online Server

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34501

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-11-24 18.202 Default_action:pass:drop
2021-11-16 18.197