Vulnerabilities > CVE-2004-0846 - Unspecified vulnerability in Microsoft Excel and Office
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS04-033.NASL |
description | The remote host has a version of Microsoft Excel that is vulnerable to a code execution issue. An attacker could exploit this flaw to execute arbitrary code on the remote host with the privileges of the user opening the file. To exploit this flaw, an attacker would need to send a malformed Excel file to a victim on the remote host and wait for him to open it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15458 |
published | 2004-10-12 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15458 |
title | MS04-033: Microsoft Excel Code Execution (886836) |
code |
|
Oval
accepted 2012-05-28T04:01:35.560-04:00 class vulnerability contributors name Matthew Burton organization The MITRE Corporation name John Hoyland organization Centennial Software name Shane Shaffer organization G2, Inc.
description Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated. family windows id oval:org.mitre.oval:def:2673 status accepted submitted 2004-10-18T12:07:00.000-04:00 title Excel 2000 File Handler Code Execution Vulnerability version 5 accepted 2012-05-28T04:01:42.612-04:00 class vulnerability contributors name Matthew Burton organization The MITRE Corporation name John Hoyland organization Centennial Software name Shane Shaffer organization G2, Inc.
description Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated. family windows id oval:org.mitre.oval:def:4226 status accepted submitted 2004-10-18T12:11:00.000-04:00 title Excel 2002 File Handler Code Execution Vulnerability version 5
References
- http://www.ciac.org/ciac/bulletins/p-009.shtml
- http://www.kb.cert.org/vuls/id/274496
- http://secunia.com/advisories/12800/
- http://marc.info/?l=bugtraq&m=109779810827096&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17683
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17653
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4226
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2673
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-033