9.3

CVE-2009-1134

Excel in 2007 Microsoft Office System SP1 and SP2; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a BIFF file with a malformed Qsir (0x806) record object, aka "Record Pointer Corruption Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftOffice Version2004 Editionmac
MicrosoftOffice Version2008 Editionmac
MicrosoftOffice Versionxp Updatesp3
MicrosoftOffice Excel Version2000 Updatesp3
MicrosoftOffice Excel Version2003 Updatesp3
MicrosoftOffice Excel Version2007 Updatesp1
MicrosoftOffice Excel Version2007 Updatesp2
MicrosoftOffice Excel Viewer Version2003 Updatesp3
MicrosoftOffice Sharepoint Server Version2007 Updatesp1 Editionx32
MicrosoftOffice Sharepoint Server Version2007 Updatesp1 Editionx64
MicrosoftOffice Sharepoint Server Version2007 Updatesp2 Editionx32
MicrosoftOffice Sharepoint Server Version2007 Updatesp2 Editionx64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 53.08% 0.979
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.