Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2011-0980 | First vendor Publication | 2011-02-10 |
| Vendor | Cve | Last vendor Modification | 2013-01-15 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 9.3 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability." |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0980 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-264 | Permissions, Privileges, and Access Controls |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:12018 | |||
| Oval ID: | oval:org.mitre.oval:def:12018 | ||
| Title: | Excel Dangling Pointer Vulnerability | ||
| Description: | Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2011-0980 |
Version: | 6 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows Server 2008 Microsoft Windows 7 |
Product(s): | Microsoft Excel 2002 Microsoft Excel 2003 |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 3 | |
| Application | 2 | |
| Application | 1 |
ExploitDB Exploits
| id | Description |
|---|---|
| 2011-11-05 | MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow |
| 2011-11-02 | Microsoft Excel 2007 SP2 Buffer Overwrite Exploit |
| 2011-04-29 | Microsoft Office Excel Axis Properties Record Parsing Buffer Overflow PoC |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 71764 | Microsoft Office Excel File Handling Dangling Pointer Remote Code Execution |
Metasploit Database
| id | Description |
|---|---|
| 2011-08-09 | MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-10 22:55:47 |
|
| 2013-01-15 17:19:47 |
|

CVE-2011-0980
(Critical)








