9.3

CVE-2008-3477

Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 5.01 Update sp4
   Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Internet Explorer Version 6
   Microsoft ≫ Windows Server 2003 Update sp1
   Microsoft ≫ Windows Server 2003 Update sp1 Edition itanium
   Microsoft ≫ Windows Server 2003 Update sp1 Edition x64
   Microsoft ≫ Windows Server 2003 Update sp2
   Microsoft ≫ Windows Xp Update gold Edition professional_x64
   Microsoft ≫ Windows Xp Update sp2
   Microsoft ≫ Windows Xp Update sp2 Edition professional_x64
   Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Internet Explorer Version 6 Update sp1
   Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Internet Explorer Version 7
   Microsoft ≫ Windows Server 2003 Update sp1
   Microsoft ≫ Windows Server 2003 Update sp1 Edition itanium
   Microsoft ≫ Windows Server 2003 Update sp1 Edition x64
   Microsoft ≫ Windows Server 2003 Update sp2
   Microsoft ≫ Windows Server 2008 Edition itanium
   Microsoft ≫ Windows Server 2008 Edition x32
   Microsoft ≫ Windows Server 2008 Edition x64
   Microsoft ≫ Windows Vista Update gold
   Microsoft ≫ Windows Vista Update gold Edition x64
   Microsoft ≫ Windows Vista Update sp1
   Microsoft ≫ Windows Xp Update gold Edition professional_x64
   Microsoft ≫ Windows Xp Update sp2
   Microsoft ≫ Windows Xp Update sp2 Edition professional_x64
   Microsoft ≫ Windows Xp Update sp3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 35.69% 0.983
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=122479227205998&w=2
http://www.us-cert.gov/cas/techalerts/TA08-288A.html
US Government Resource
http://secunia.com/advisories/32211
Patch
Vendor Advisory
http://www.securitytracker.com/id?1021044
http://www.vupen.com/english/advisories/2008/2808
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-057
https://exchange.xforce.ibmcloud.com/vulnerabilities/45581
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=746
http://www.securityfocus.com/bid/31702
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/45566
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5870