42723 : Microsoft Excel SLK File Import Unspecified Arbitrary Code Execution
Printer | http://osvdb.org/42723 | Email This | Edit Vulnerability

Views This Week

1

Views All Time

628

Info

Last Modified

8 months ago

Percent Complete

100%

Disclosure

Mar 11, 2008

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Mar 11, 2008

Description

A code execution flaw exists in Excel. The Import function fails to validate SLK files resulting in code execution via an unspecified vector. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Context Dependent

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
Office
Watch-list
2004 for Mac
2008 for Mac
Excel
Watch-list
2000 SP3

References

Tools & Filters

Snort

13583 13584 13585

Nessus

31413

Credit

  • Yoshiya Sasaki -

Blogs

Sat Mar 22 07:18:41 -0500 2008 | Microsoft re-issues Excel patch

from: dralnux.com

Microsoft re-issues Excel patch Posted by Adrian in Microsoft, Security Tags: ... of an unprotected PC’s systems. The update, MS08-014, was supposed to fix the zero-day flaw

Wed Mar 19 14:40:00 -0500 2008 | March 2008 MS08-014 Re-release

from: The Microsoft Security Response Center (MSRC)

Hello, this is Tim Rains. Very quickly, I wanted to let you know that we've just re-released MS08-014 for Microsoft Office Excel 2003 Service Pack ... distribution channels as the original MS08-014 security update. It is also supported by the same

Mon Mar 17 09:48:53 -0500 2008 | Excel non calculat

from: vowe dot net

After you install security update MS08-014, Excel 2003 calculations return an incorrect result when a Real Time Data source is used in a user-defined Visual Basic for Applications function More

Mon Mar 17 01:27:58 -0500 2008 | Microsoft Excel patch may lead to to calculation errors

from: Zero Day | ZDNet.com

Microsoft plugged more than a few vulnerabilities in Excel last week, but the trade off may be calculation errors. Microsoft’s Bill Sisk said in a post late Friday following the software giant’s latest patch batch: I wanted to let you know that we have updated bulletin MS08-014 to provide additional information

Sun Mar 16 03:09:52 -0500 2008 | Buggy Microsoft Excel Patch Causes Bad Math

from: MicroTech360 | Technology News!

Buggy Microsoft Excel Patch Causes Bad Math Articles, Microsoft, Software No Comments » A bug in this week’s MS08-014 patch causes Excel to return zeroes instead of the correct number when certain types of macros are run within the program. The issue, which

Sat Mar 15 23:52:31 -0500 2008 | Just-patched Excel makes calculation mistakes

from: Microsoft News Weblog

Just-patched Excel makes calculation mistakes March 16th, 2008 Microsoft Corp. yesterday told Excel users that one of the 12 patches issued Tuesday causes the spreadsheet to make mistakes in some calculations. According to a more detailed addition to MS08-014, Excel 2003

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use