CVE-2008-0113
published 2008-03-11CVE-2008-0113: Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document…
PriorityP258critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
42.23%
98.5th percentile
Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel_viewer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation targets Excel documents with malformed cell comments triggering memory corruption; inspect Excel files for anomalous or oversized cell comment structures. ↗
- →Exploit payload spawns calc.exe as a proof-of-concept; monitor for unexpected calc.exe processes spawned from Office application processes (e.g., Excel, PowerPoint). ↗
- →Attack vector is a user-assisted file open of a malicious .PPT or Excel document; monitor for Office processes opening files from untrusted/remote locations followed by anomalous child process creation. ↗
- ·The NVD entry and exploit-db entry reference overlapping but distinct issues: CVE-2008-0113 specifically covers Excel Viewer 2003 cell comment parsing memory corruption, while the exploit-db entry (5320) targets a .PPT buffer overflow under MS08-016 — these are separate vulnerabilities sharing the same advisory bundle. ↗
- ·Exploit is confirmed effective only against Office XP SP3 with updates prior to 03/11/08; patched systems are not affected. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=120585858807305&w=2http://secunia.com/advisories/29321http://www.securityfocus.com/archive/1/489415/100/0/threadedhttp://www.securitytracker.com/id?1019578http://www.us-cert.gov/cas/techalerts/TA08-071A.htmlhttp://www.vupen.com/english/advisories/2008/0848/referenceshttp://www.zerodayinitiative.com/advisories/ZDI-08-008https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-016https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5421http://marc.info/?l=bugtraq&m=120585858807305&w=2http://secunia.com/advisories/29321http://www.securityfocus.com/archive/1/489415/100/0/threadedhttp://www.securitytracker.com/id?1019578http://www.us-cert.gov/cas/techalerts/TA08-071A.htmlhttp://www.vupen.com/english/advisories/2008/0848/referenceshttp://www.zerodayinitiative.com/advisories/ZDI-08-008https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-016https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5421
2008-03-11
Published