Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a malformed object record, related to a "stray reference," aka "Excel Linked List Corruption Vulnerability."
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.us-cert.gov/cas/techalerts/TA11-102A.html | third party advisory us government resource |
http://secunia.com/advisories/39122 | third party advisory vendor advisory |
http://secunia.com/advisories/43231 | third party advisory vendor advisory |
http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsoft | |
http://zerodayinitiative.com/advisories/ZDI-11-041/ | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12595 | vdb entry signature |
http://www.securitytracker.com/id?1025337 | vdb entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-021 | vendor advisory |
http://osvdb.org/70904 | vdb entry |
http://www.vupen.com/english/advisories/2011/0940 | vdb entry vendor advisory |