Multiple vulnerabilities have been identified in Microsoft Office, which could be exploited by remote attackers to execute arbitrary commands.
The first issue is due to a memory corruption error in Excel when handling a malformed range, which could be exploited by attackers to compromise a vulnerable system via a malicious document [...]
Affected Products
Microsoft Office 2000 Service Pack 3
Microsoft Word 2000
Microsoft Excel 2000
Microsoft Outlook 2000
Microsoft PowerPoint 2000
Microsoft Office 2000 MultiLanguage Packs
Microsoft Office XP Service Pack 3
Microsoft Word 2002
Microsoft Excel 2002
Microsoft Outlook 2002
Microsoft PowerPoint 2002
Microsoft Office XP Multilingual User Interface Packs
Microsoft Office 2003 Service Pack 1
Microsoft Office 2003 Service Pack 2
Microsoft Excel 2003
Microsoft Excel 2003 Viewer
Microsoft Works Suite 2000
Microsoft Works Suite 2001
Microsoft Works Suite 2002
Microsoft Works Suite 2003
Microsoft Works Suite 2004
Microsoft Works Suite 2005
Microsoft Works Suite 2006
Microsoft Office X for Mac
Microsoft Excel X for Mac
Microsoft Office 2004 for Mac
Microsoft Excel 2004 for Mac
Credits
Vulnerabilities reported by Peter Winter-Smith, Ollie Whitehouse, Arnaud Dovi, Dejun Meng, Eyas and the vendor.
ChangeLog
2006-03-15 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.