CVE-2010-0264Code Injection in Microsoft Excel

CWE-94Code Injection4 documents4 sources
Severity
9.3CRITICALNVD
EPSS
56.6%
top 1.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMay 2

Description

Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-277j-v92f-57q6: Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format,2022-05-02
CVEList
CVE-2010-0264: Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format,2010-03-10

💥Exploits & PoCs

1
Exploit-DB
Seattle Lab Mail (SLmail) 5.5 - POP3 'PASS' Remote Buffer Overflow (Metasploit)2010-04-30
CVE-2010-0264 — Code Injection in Microsoft Excel | cvebase