All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
About Hackers
Analysis
News
Glossary
Weblog



 
Virus Encyclopedia
Virus Encyclopedia

Learn about worms, viruses, Trojans and more in our Virus Encyclopedia.

About Spam
About Spam

Read about spam and spammers in our About Spam section.

 

  Home / Hackers / About Hackers / Software Vulnerabilities / Examples and Descriptions / SA31454

Microsoft Office Excel Multiple Vulnerabilities

Secunia ID

SA31454

CVE-ID

CVE-2008-3003, CVE-2008-3004, CVE-2008-3005, CVE-2008-3006

Release Date

12 Aug 2008

Last Change

13 Aug 2008

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Microsoft Excel 2000
Microsoft Excel 2002
Microsoft Excel 2003
Microsoft Excel Viewer 2003
Microsoft Office 2000
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2004 for Mac
Microsoft Office 2007
Microsoft Office 2008 for Mac
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Excel 2007
Microsoft Office Excel Viewer 2007
Microsoft Office XP

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.


Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.


Description

Multiple vulnerabilities have been reported in Microsoft Excel, which can be exploited by malicious people to gain knowledge of sensitive information or compromise a user's system.

1) Index values in "AxesSet" records are not properly validated when loading Excel files into memory. This can be exploited to corrupt memory via a specially crafted Excel file.

Successful exploitation of the vulnerability may allow execution of arbitrary code.

2) An error during processing of "FORMAT" records when loading Excel files into memory can be exploited to corrupt memory via a specially crafted Excel file containing an out-of-bounds array index.

Successful exploitation of the vulnerability may allow execution of arbitrary code.

3) An error during parsing of Country (0x8c) record values when loading Excel files into memory can be exploited to corrupt memory via a specially crafted Excel file.

Successful exploitation of the vulnerability may allow execution of arbitrary code.

4) Passwords strings to remote data sources are not being properly deleted even when configured to not store credentials. This can be exploited to access secured remote data sources by opening an ".xlsx" file.

Solution

Apply patches.

Excel 2000 SP3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=4bf8688e-e5b9-4e53-a1a1-8cf1acfdb80b

Excel 2002 SP3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=9BBF7550-F5C4-4B9B-BD86-1E7BE6C42EB5

Excel 2003 SP2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=fc612e9a-bdf3-4952-8ada-0de5a50973f0

Excel 2003 SP3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=fc612e9a-bdf3-4952-8ada-0de5a50973f0

Excel 2007:
http://www.microsoft.com/downloads/details.aspx?FamilyId=2753e8d6-e156-49ef-af2d-4c521c808ffd

Excel 2007 SP1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=2753e8d6-e156-49ef-af2d-4c521c808ffd

Microsoft Office Excel Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=d7ed9e75-15f2-4950-98b3-93023ba0f4c1

Microsoft Office Excel Viewer 2003 SP3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=d7ed9e75-15f2-4950-98b3-93023ba0f4c1

Microsoft Office Excel Viewer:
http://www.microsoft.com/downloads/details.aspx?FamilyId=b574d906-7f09-49b0-80bf-e84dee8c4583

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7afdae9b-9c74-4af7-9844-0e54221ea3b9

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7afdae9b-9c74-4af7-9844-0e54221ea3b9

Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyId=EBD3AF0C-3F62-4D18-BF45-881655683BD5

Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyId=9515C70D-BE80-4ADE-856A-EA542F7D84E1

Reported by

1) An anonymous person, reported via VeriSign iDefense VCP.
2) An anonymous person, reported via VeriSign iDefense VCP.
3) An anonymous person, reported via TippingPoint and the Zero Day Initiative.
4) The vendor credits Jeremy Funk.

Original Advisory

MS08-043 (KB954066):
http://www.microsoft.com/technet/security/Bulletin/MS08-043.mspx

iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=740
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=741

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-08-048/




 

Copyright © 1996 - 2009
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com