9.3

CVE-2007-0028

Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability."  NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Excel Version 2000
Microsoft ≫ Office Version 2000 Update sp3
Microsoft ≫ Excel Version 2002
Microsoft ≫ Office Version xp Update sp3
Microsoft ≫ Excel Version 2003
Microsoft ≫ Office Version 2003 Update sp2
Microsoft ≫ Excel Viewer Version 2003
Microsoft ≫ Works Version 2004
Microsoft ≫ Works Version 2005
Microsoft ≫ Office Version 2004 Edition mac
Microsoft ≫ Office Version v.x Edition mac
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 33.19% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/archive/1/457274/100/0/threaded
http://www.us-cert.gov/cas/techalerts/TA07-009A.html
US Government Resource
http://www.vupen.com/english/advisories/2007/0103
Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002
http://secunia.com/advisories/23676
Vendor Advisory
http://securitytracker.com/id?1017485
http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html
http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html
http://www.kb.cert.org/vuls/id/493185
Patch
US Government Resource
http://www.osvdb.org/31249
http://www.securityfocus.com/bid/21952
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A768