Vulnerabilities > CVE-2008-3477 - Resource Management Errors vulnerability in Microsoft Internet Explorer 5.01/6/7
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 | |
OS | 15 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS08-057.NASL |
description | The remote host is running a version of Microsoft Excel that is subject to various flaws which could allow arbitrary code to be run. An attacker may use this to execute arbitrary code on this host. To succeed, the attacker would have to send a rogue file to a user of the remote computer and have it open it with Microsoft Excel. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 34402 |
published | 2008-10-15 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/34402 |
title | MS08-057: Microsoft Excel Multiple Method Remote Code Execution (956416) |
code |
|
Oval
accepted | 2014-06-30T04:11:08.492-04:00 | ||||||||||||||||
class | vulnerability | ||||||||||||||||
contributors |
| ||||||||||||||||
definition_extensions |
| ||||||||||||||||
description | Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability." | ||||||||||||||||
family | windows | ||||||||||||||||
id | oval:org.mitre.oval:def:5870 | ||||||||||||||||
status | accepted | ||||||||||||||||
submitted | 2008-10-14T13:33:00 | ||||||||||||||||
title | Calendar Object Validation Vulnerability | ||||||||||||||||
version | 13 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 31702 CVE(CAN) ID: CVE-2008-3477 Excel是微软Office办公套件中的电子表格工具。 Excel处理VBA性能缓存的方式中存在一个远程执行代码漏洞。如果用户在VBA性能缓存中打开一个特制Excel文件,该漏洞可能触发堆溢出、内存破坏、无效数组索引或整数溢出等。成功利用此漏洞的攻击者可以完全控制受影响的系统。攻击者可随后安装程序;查看、更改或删除数据;或者创建拥有完全用户权限的新帐户。 Microsoft Excel 2003 SP3 Microsoft Excel 2003 SP2 Microsoft Excel 2002 SP3 Microsoft Excel 2000 SP3 Microsoft --------- Microsoft已经为此发布了一个安全公告(MS08-057)以及相应补丁: MS08-057:Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416) 链接:<a href=http://www.microsoft.com/technet/security/Bulletin/MS08-057.mspx?pf=true target=_blank>http://www.microsoft.com/technet/security/Bulletin/MS08-057.mspx?pf=true</a> |
id | SSV:4249 |
last seen | 2017-11-19 |
modified | 2008-10-16 |
published | 2008-10-16 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-4249 |
title | Microsoft Excel日历对象验证远程代码执行漏洞(MS08-057) |
References
- http://secunia.com/advisories/32211
- http://www.securityfocus.com/bid/31702
- http://www.securitytracker.com/id?1021044
- http://marc.info/?l=bugtraq&m=122479227205998&w=2
- http://www.us-cert.gov/cas/techalerts/TA08-288A.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=746
- http://www.vupen.com/english/advisories/2008/2808
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45581
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45566
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5870
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-057