9.3

CVE-2011-0979

Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a malformed object record, related to a "stray reference," aka "Excel Linked List Corruption Vulnerability."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftExcel Version- Update- Editionx64
MicrosoftExcel Version2002 Updatesp3
MicrosoftExcel Version2003 Updatesp3
MicrosoftExcel Version2007 Updatesp2
MicrosoftExcel Version2010
MicrosoftExcel Viewer Version- Updatesp2
MicrosoftOffice Version2004 Editionmac
MicrosoftOffice Version2008 Editionmac
MicrosoftOffice Version2011 Editionmac
MicrosoftOffice Compatibility Pack Version2007 Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 66.75% 0.985
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.