Bird_banner_small4
Microsoft Office Excel Pivot Item Index Boundary Error Memory Corruption
TSL ID TSL20100810-27
CVE ID(s) CVE-2010-2562
Severity High
Description

A memory corruption vulnerability exists in Microsoft Office Excel. The vulnerability is due to improper parsing of a malformed Excel file. Remote attackers can exploit this vulnerability by enticing target users to open a malicious Excel file, potentially causing arbitrary code to be injected and executed in the security context of the current user.

In an attack scenario where arbitrary code is successfully injected and executed on the target machine the behaviour of the target is dependent on the intention of the malicious code. If such an attack is not executed successfully, the vulnerable application may terminate as a result of invalid memory access.

Microsoft has provided patches to address this vulnerability at:

http://www.microsoft.com/technet/security/bulletin/ms10-057.mspx

Affected Products
  • Microsoft Office 2002
  • Microsoft Office 2003
  • Microsoft Office Open XML File Format Converter for Mac
  • Microsoft Office 2004 for Mac .
  • Microsoft Office 2008 for Mac .
CVSS Score Base 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P):
  • Access vector is NETWORK
  • Access complexity is MEDIUM
  • Level of authentication required is NONE
  • Impact of this vulnerability on data confidentiality is PARTIAL
  • Impact of this vulnerability on data integrity is PARTIAL
  • Impact of this vulnerability on data availability is PARTIAL
Temporal 5.0 (E:U/RL:OF/RC:C):
  • The exploitability level of this vulnerability is UNPROVEN
  • The remediation level of this vulnerability is OFFICIAL FIX
  • The report confidence level of this vulnerability is CONFIRMED
Identifiers
BID
Microsoft Security Bulletin
OSVDB
Related Threats