CVE-2009-0100

CWE-3998 documents5 sources
Severity
9.3CRITICAL
EPSS
57.2%
top 1.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateMay 2

Description

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel in Microsoft Office 2004 and 2008 for Mac; Microsoft Office Excel Viewer and Excel Viewer 2003 SP3; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 do not properly parse the Excel spreadsheet file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that contains a malformed object with "an offset and a two-byte value" that trigger a memory c

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDmicrosoft/office_excel4 versions+3
NVDmicrosoft/office2004, 2008+1

🔴Vulnerability Details

2
GHSA
GHSA-4mhf-pw3q-x8rp: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel in Microsoft Office 2004 and 2008 for Mac; Microsoft Office Excel Viewer and2022-05-02
CVEList
CVE-2009-0100: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel in Microsoft Office 2004 and 2008 for Mac; Microsoft Office Excel Viewer and2009-04-15

💥Exploits & PoCs

2
Exploit-DB
Zabbix Server - Multiple Vulnerabilities2009-12-14
Exploit-DB
Zabbix Agent < 1.6.7 - Remote Bypass2009-12-14

💬Community

3
Bugzilla
CVE-2009-5054 php-Smarty: Does not consider the umask value when setting the permissions of files2011-10-25
Bugzilla
CVE-2009-5052 php-Smarty: Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 62011-10-25
Bugzilla
CVE-2009-4026 CVE-2009-4027 kernel: mac80211: fix spurious delBA handling2009-11-25
CVE-2009-0100 (CRITICAL CVSS 9.3) | Microsoft Office Excel 2000 SP3 | cvebase.io