CVE-2010-0262

high

Description

Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8562

https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-017

http://www.us-cert.gov/cas/techalerts/TA10-068A.html

http://www.securitytracker.com/id?1023698

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=860

Details

Source: Mitre, NVD

Published: 2010-03-10

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High