42732 : Microsoft Excel Macro Validation Unspecified Code Execution
Printer | http://osvdb.org/42732 | Email This | Edit Vulnerability

Views This Week

8

Views All Time

966

Info

Last Modified

4 months ago

Percent Complete

100%

Disclosure

Mar 11, 2008

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Mar 11, 2008

Description

Excel contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when Excel fails to validate specially-crafted macros. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch
Exploit: Exploit Available
Disclosure: Vendor Verified, Discovered in the Wild
OSVDB: Context Dependent

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
Office
Watch-list
2004 for Mac
Excel
Watch-list
2000 SP3
2003 SP2
XP SP3
Excel Viewer
Watch-list
2003

References

Tools & Filters

Nessus

31413

Credit

  • Mike Scott -
  • Matt Richard -

Blogs

2008/04/12 19:01:23 | April Fools' Day threats

from: Cool Windows XP tips & tricks

Its fun to make a prank virus, but getting the real thing is not so great ... and that all Windows updates are installed. More... 2. Exploit targeting MS08-014 flaw released A public exploit ... messaging and file sharing. The issue was patched in the MS08-014 bulletin -- ensure that Excel updates

2008/04/11 10:50:08 | Troj_exdrop.b

from: The UNIX Forums

This Trojan is a specially crafted .XLS file that takes advantage of the following software vulnerability to drop possibly malicious files:Microsoft Security Bulletin MS08-014 The said vulnerability allows a malicious .XLS file to drop and execute an embedded executable file. More...

2008/04/03 05:45:58 | March Malware Roundup

from: TrendLabs | Malware Blog - by Trend Micro

For those of you who have read last month’s malware roundup, Fidel Castro is still alive. Thanks to some malware authors, a spammed email message spread in the early weeks of March, claiming that the old Cuban leader had already passed away. As expected,

2008/04/01 12:15:48 | MS08-014 : The Case of the Uninitialized Stack Variable Vulnerability

from: 安全代码

MS08-014, CVE 2008-0081, addresses a vulnerability in Excel whose root cause is an uninitialized stack variable.  You probably have seen these types of compiler warnings before: C:\temp>cl

2008/03/27 15:38:31 | Drive By Downloads: Links and Insights

from: Security to the Core | Arbor Networks Security

I spend a lot of my time looking at malicious code and where it gets loaded, but I don’t get to spend much time digging into big, ... Vulnerabilities fixed in MS08-014, and the exploit code has been found being used in the wild. For a good

2008/03/26 13:55:44 | Firefox and Thunderbird Vulns, Excel Exploit

from: MSI :: State of Security

Vulnerabilities have been reported in Mozilla Firefox and Thunderbird ... described in MS08-014. Microsoft has already released an update for this, so if it hasn’t been installed

2008/03/26 11:37:59 | Hackers seize on Excel vulnerability

from: InfoWorld - Security Reviews and Security Product Information

Researchers at Symantec said late Tuesday they've spotted a Web site that tries to exploit computers lacking one of the recently issued patches for ... , the vendor said. To protect computers, users are advised to apply MS08-014, the batch of patches

2008/03/24 06:59:09 | Security news roundup: Spybot Search & Destroy scans for rootkits, multiple patches from Apple

from: IT Security | TechRepublic.com

Here’s a collection of recent security vulnerabilities and alerts, which covers news that Spybot Search & ... for Microsoft Office Excel 2003 SP2 and SP3. The original version of MS08-014 that was released on March 11

2008/03/23 08:15:13 | Episode 17 - Selling Linux - Part 1

from:

This week, we will talk with a provider who specializes in Linux and Linux based solutions and find out how we can provide open source solutions to ... results in calculations. The patch was for Microsoft Security Bulletin MS08-014, a vulnerability

2008/03/21 13:17:00 | Excel 2003: Real Time Data Multiplication Errors

from: Tech Experts Blog :: Main Page

[ View Article] Excel 2003: Real Time Data Multiplication Errors by ThomasFox on Fri 21 Mar 2008 09: ... for Applications, according to Microsoft. The patch, known as MS08-014, was released for Excel 2003

2008/03/18 18:26:12 | MS updates the Excel update

from: PC Security: A blog site with a computer security theme!!

Since issuing this patch last Tuesday, Microsoft has twice updated MS08-014: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution. In the first case, Microsoft noted why the update

2008/03/10 05:50:55 | Olympic Fans May Fall for Unpatched MS Excel Vuln

from: TrendLabs | Malware Blog - by Trend Micro

XLS files specially designed to exploit a currently unpatched vulnerability in Microsoft Excel (identified as CVE-2008-0081) are reportedly being sent as email attachments in the wild

2008/03/10 05:50:55 | Olympic Fans May Fall for Unpatched MS Excel Vuln

from: Spyware removal resources

Olympic Fans May Fall for Unpatched MS Excel Vuln XLS files specially designed to exploit a currently unpatched vulnerability in Microsoft Excel (identified as CVE-2008-0081) are reportedly being sent as email attachments in the wild. The attachments, which arrive either as OLYMPIC.XLS or SCHEDULE.XLS are capable of dropping and executing

2008/03/15 10:00:03 | Buggy Microsoft Excel Patch Causes Bad Math

from: Miles Associates LLC » Jim Miles - Information Technology & IT Security Consultant

Buggy Microsoft Excel Patch Causes Bad Math Posted in IT Infrastructure, Security  From CIO ... a bug in the recent MS08-014 patch is causing Excel to return zeroes instead of the correct number

2008/03/14 10:28:09 | Update To Excel Update

from: PC Magazine Security Watch - Tech Security News, Reviews, Patches and Advice

There are some problems and some non-problems with MS08-014.

2008/03/13 09:36:00 | Microsoft Updates for March

from: PandaLabs, everything you need to know about Internet threats

As usual, every second Tuesday Microsoft published security updates for its products. On 11th March, Microsoft published four updates (from MS08-014 to MS08-017), all of them rated as critical and affecting Microsoft Office suite ... the following links: MS08-014: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution

2008/03/11 22:20:12 | Everybody’s an expert…

from: Tripwise

Any one of the references in Juha-Matti Laurio’s post about MS08-014 over at the SecuriTeam blog should be sufficient to warrant an analysis of one’s environment to see if the patch is applicable

2008/03/11 21:09:50 | March 2008 Monthly Release

from: TechnO wOrld InC - The Best Technical Encyclopedia Online!

March 2008 Monthly Release March 2008 Bulletin. all are for Office and all have a maximum severity rating of Critical. MS08-014: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution. Note that this... Continue this atic...

2008/03/11 21:07:18 | Information Microsoft patches a dozen bugs in Office

from: DN For United Mankind Forum

Microsoft patches a dozen bugs in Office Fixes a 2-month-old Excel exploit, ... as "important," the second-highest rating. There's no question that MS08-014, the bulletin that fixes

2008/03/12 08:06:00 | Microsoft Security Bulletin Summary for March 2008

from: MVP Jubo Security Blog

Yesterday, March 11th, Microsoft released 4 critical updates. So far I have it installed on five XP Pro SP2 machines without any problems. If you haven't done it yet then point your mouse to Microsoft Update to download and install these patches: MS08-014 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (949029

2008/03/12 07:01:56 | Microsoft Security Bulletin MS08-014 - Critical- Topic: linkdirectoryNews

from: linkdirectory.org.in

Microsoft Security Bulletin MS08-014 - Critical- Topic: linkdirectoryNews March 12th, 2008 This security update is rated Critical for Microsoft Office Excel 2000 Service Pack 3 and rated Important

2008/03/12 01:55:32 | Microsoft Security Bulletin Summary for March 2008

from: Tommy’s Security Weblog

This bulletin summary lists security bulletins released for March 2008. Critical Security Bulletins Microsoft Security Bulletin MS08-014 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (949029) Microsoft Security Bulletin MS08-015

2008/03/12 01:49:43 | Security Bulletin Release: March 2008

from: Jeff Alexander's Weblog

[ security bulletin] Please see below for details of this months security bulletin ... . Bulletin Number Maximum Severity Affected Products Impact Technical Details MS08-014 Critical

2008/03/12 01:40:31 | Microsoft Overhauls Office; Fixes a Dozen Vulnerabilities

from: Bardissi Enterprises Blog

Severity: High 11 March, 2008 Summary: These vulnerabilities affect: Most current versions of Microsoft Office for Windows, ... : MS08-014: Multiple Excel vulnerabilities. This bulletin describes seven vulnerabilities involving

2008/03/12 01:08:17 | OfficeCat Update Available

from: Snort - the de facto standard for intrusion detection/prevention

OfficeCat has been updated to provide detection for CVE entries 2008-0081, 2008-0111, 2008-0114, 2008-0115, 2008-0116, 2008-0117 and 2008-0118. Which are noted in Microsoft Security Advisories MS08-014 and MS08-016. For more details and to download OfficeCat for Windows and Linux, see the OfficeCat page.

2008/03/11 22:52:55 | Patches for Patches for Patches for Office

from: ProCookie Technology Blog

Patches for Patches for Patches for Office Written by snuffy on March 11, 2008 – 10:52 pm - Microsoft delivers 12 patches to plug Office; 7 for Excel flaws Microsoft on Tuesday delivered several patches to fix critical vulnerabilities in Office including a well-publicized Excel flaw. In the first bulletin (MS08-014), Microsoft

2008/03/11 22:43:39 | Patch Tuesday Wednesday (MAR-2008)

from: Visible Procrastinations

It’s Black Tuesday again! This month we have 4xCritical patches for our entertainment, ... . Bulletin KB number Description Severity Impact Software MS08-014 949029 Vulnerabilities ... . One of these vulnerabilities has been seen within in-the-wild zero-day attacks. — eEye 5 PATCH NOW: MS08-014 LINKS

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use