cbcvebase.
CVE-2010-1245
published 2010-06-08

CVE-2010-1245: Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows…

PriorityP260critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
22.36%
97.4th percentile
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.

Affected

7 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftoffice
microsoftoffice
microsoftoffice_compatibility_pack
msrcmicrosoft_edge

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/15148.rar
filenamemoaub-29-exploit.rar
  • Detect crafted Excel files containing a malformed SxView record, which triggers heap memory corruption in Excel 2002 SP3 and related versions.
  • Flag Excel files with a crafted SxView record as potentially exploiting CVE-2010-1245; the vulnerability involves improper validation of structures within the SxView record.
  • ·The vulnerability is described as 'unspecified' regarding the exact structures validated, limiting precise byte-level signature development.
  • ·CVE-2010-1245 is a distinct vulnerability from CVE-2010-0824 and CVE-2010-0821 despite all three involving Excel SxView record parsing; detections should not conflate them.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.