Vulnerabilities > CVE-2007-0031 - Remote Code Execution vulnerability in Microsoft Excel Malformed Palette Record
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 11 |
Exploit-Db
description | Microsoft Excel Malformed Palette Record DoS PoC (MS07-002). CVE-2007-0031. Dos exploit for windows platform |
id | EDB-ID:3193 |
last seen | 2016-01-31 |
modified | 2007-01-25 |
published | 2007-01-25 |
reporter | LifeAsaGeek |
source | https://www.exploit-db.com/download/3193/ |
title | Microsoft Excel - Malformed Palette Record DoS PoC MS07-002 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS07-002.NASL |
description | The remote host is running a version of Microsoft Excel that is subject to various flaws that could allow arbitrary code to be run. An attacker may use this to execute arbitrary code on this host. To succeed, the attacker would have to send a rogue file to a user of the remote computer and have it open it with Microsoft Excel. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 23998 |
published | 2007-01-09 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/23998 |
title | MS07-002: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (927198) |
code |
|
Oval
accepted | 2012-05-28T04:02:30.976-04:00 | ||||||||||||
class | vulnerability | ||||||||||||
contributors |
| ||||||||||||
definition_extensions |
| ||||||||||||
description | Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries. | ||||||||||||
family | windows | ||||||||||||
id | oval:org.mitre.oval:def:753 | ||||||||||||
status | accepted | ||||||||||||
submitted | 2007-01-10T02:08:37 | ||||||||||||
title | Excel Malformed Palette Record Vulnerability | ||||||||||||
version | 6 |
Saint
bid | 21922 |
description | Microsoft Excel PALETTE record buffer overflow |
id | win_patch_excel07002 |
osvdb | 31258 |
title | excel_palette |
type | client |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=461
- http://securitytracker.com/id?1017487
- http://www.kb.cert.org/vuls/id/625532
- http://www.osvdb.org/31258
- http://www.securityfocus.com/archive/1/457274/100/0/threaded
- http://www.securityfocus.com/bid/21922
- http://www.us-cert.gov/cas/techalerts/TA07-009A.html
- http://www.vupen.com/english/advisories/2007/0103
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A753