New Search

Excel Conditional Expression Parsing Vulnerability

oval:org.mitre.oval:def:12974

Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004 2008 and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; Office Compatibility Pack for Word Excel and PowerPoint 2007 File Formats SP2; Excel Services on Office SharePoint Server 2007 SP2; Excel Services on Office SharePoint Server 2010 Gold and SP1; and Excel Web App 2010 Gold and SP1 do not properly parse conditional expressions associated with formatting requirements which allows remote attackers to execute arbitrary code via a crafted spreadsheet aka "Excel Conditional Expression Parsing Vulnerability."

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows 7
  • Microsoft Windows Server 2008
  • Microsoft Windows Vista
  • Microsoft Windows XP
  • Microsoft Windows Server 2003
  • Microsoft Windows Server 2008 R2
Class:
vulnerability
Reference(s):
  • CVE-2011-1989
Product(s):
  • Microsoft Office Compatibility Pack
  • Microsoft Office SharePoint Server 2007
  • Microsoft Office Excel Viewer
  • Microsoft Office Web Apps 2010
  • Microsoft Excel 2003
  • Microsoft Office 2007
  • Microsoft Office 2010
  • Microsoft Excel 2010
  • Microsoft Office SharePoint Server 2010
  • Microsoft Excel 2007