cbcvebase.
CVE-2010-0824
published 2010-06-08

CVE-2010-0824: Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a…

PriorityP260critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
22.39%
97.4th percentile
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftoffice
microsoftoffice
microsoftoffice_compatibility_pack

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2010-0824 is related to Excel record parsing memory corruption; the SxView record in Excel files is the attack vector — inspect Excel files with crafted SxView records for improper structure validation
  • ·The provided sources primarily describe CVE-2010-0821 (SxView record) and CVE-2010-1248 (WOPT record), not CVE-2010-0824 directly. No concrete IOCs (hashes, IPs, domains, signatures) specific to CVE-2010-0824 are present in the supplied documents.
  • ·The Exploit-DB entry (15065) and its PoC RAR archive reference CVE-2010-1248 (WOPT record heap corruption in Excel 2002 SP3), not CVE-2010-0824. Do not conflate these CVEs during detection rule authoring.
  • ·The PoC binary is hosted at the following URL and should be treated as a malicious sample reference only — do not execute outside a controlled environment.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat4.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.