|
Multiple vulnerabilities have been reported in Microsoft Excel, which can be exploited by malicious people to gain knowledge of sensitive information or compromise a user's system. 1) Index values in "AxesSet" records are not properly validated when loading Excel files into memory. This can be exploited to corrupt memory via a specially crafted Excel file. Successful exploitation of the vulnerability may allow execution of arbitrary code. 2) An error during processing of "FORMAT" records when loading Excel files into memory can be exploited to corrupt memory via a specially crafted Excel file containing an out-of-bounds array index. Successful exploitation of the vulnerability may allow execution of arbitrary code. 3) An error during parsing of Country (0x8c) record values when loading Excel files into memory can be exploited to corrupt memory via a specially crafted Excel file. Successful exploitation of the vulnerability may allow execution of arbitrary code. 4) Passwords strings to remote data sources are not being properly deleted even when configured to not store credentials. This can be exploited to access secured remote data sources by opening an ".xlsx" file.
|