Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.us-cert.gov/cas/techalerts/TA08-225A.html | third party advisory us government resource |
http://www.securityfocus.com/bid/30641 | vdb entry |
http://marc.info/?l=bugtraq&m=121915960406986&w=2 | vendor advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-043 | vendor advisory |
http://www.securitytracker.com/id?1020669 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5951 | signature vdb entry |
http://secunia.com/advisories/31454 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2008/2347 | vdb entry vendor advisory |