cbcvebase.
CVE-2010-1247
published 2010-06-08

CVE-2010-1247: Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813)…

PriorityP259critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
22.39%
97.4th percentile
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftoffice
microsoftoffice
microsoftoffice_compatibility_pack

Detection & IOCsextracted from sources · hover to see the quote

filenameexploit.xls
bytes
\x81\xc4\x24\x16\x00\x00
bytes
\xeb\x06\x41\x41
  • Malicious XLS file exploiting Excel RTD Memory Corruption; look for crafted .xls files delivered to Excel 2002 SP3 / Office 2004/2008 for Mac targets
  • Exploit payload uses an egg-hunter technique combined with a stack pivot (add esp, 0x1624) followed by a RET gadget; monitor for anomalous ESP manipulation in Excel process memory
  • Exploit writes NOP-padded egg-hunter and shellcode blobs into a crafted .xls file; AV/sandbox scanning of XLS attachments should flag NOP sled patterns adjacent to egg-hunter stubs
  • CVE-2010-1247 is a buffer overflow triggered by a malformed ExternName (record type 0x23) in an Excel file; inspect XLS BIFF records for anomalous 0x23 record sizes
  • ·NVD source URL references CVE-2010-1249, not CVE-2010-1247; the ExternName (0x23) record detail and affected product list may describe a related but distinct vulnerability — verify applicability to CVE-2010-1247 before operationalising
  • ·Exploit-DB PoC (14966) is labelled 'Excel RTD - Memory Corruption' without explicit CVE attribution; confirm it maps to CVE-2010-1247 before using its IOCs as definitive signatures
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.