| TSL ID | TSL20090609-01 |
| CVE ID(s) | CVE-2009-0559 |
| Severity | High |
| Description | A remotely exploitable vulnerability has been discovered in Microsoft Office Excel products. Specifically, the vulnerability is due to a design error encountered when parsing Excel files which contain malformed records. Remote attackers can exploit this vulnerability by enticing target users to open a malicious Excel file. A remote attacker can exploit the vulnerability by sending a malicious Excel file to the target system and enticing the target user to open it. A successful code execution attempt will result in the execution of arbitrary code within the security privileges of the currently logged in user. An unsuccessful attack attempt will result in abnormal termination of the Microsoft Office Excel application. The vendor, Microsoft, has published a patch which eliminates the vulnerability. Reference: http://www.microsoft.com/technet/security/bulletin/ms09-021.mspx This vulnerability was originally reported at: http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx The Common Vulnerabilities and Exposures (CVE) Editorial Board has assigned candidate number CVE-2009-0559 to track this vulnerability |
| Affected Products |
|
| CVSS Score |
Base 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P):
|
| Identifiers | |
| Related Threats |