CVE-2010-1248
published 2010-06-08CVE-2010-1248: Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed…
PriorityP262critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
27.18%
97.8th percentile
Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | office | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect malformed HFPicture (record type 0x866) in Excel files; a crafted record triggers a buffer overflow leading to remote code execution. ↗
- →Inspect Excel BIFF records for anomalous WOPT record parsing that causes heap memory corruption; targets Excel 2002 SP3. ↗
- →Flag Excel files exploiting HFPicture record parsing for remote code execution; specifically targets Excel 2002 SP3. ↗
- ·Affected versions are Excel 2002 SP3 and Office 2004 for Mac; detections should be scoped accordingly. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
exploitdb·2010-09-21·CVSS 9.3
CVE-2010-1248 [CRITICAL] Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
---
'''
__ __ ____ _ _ ____
| \/ |/ __ \ /\ | | | | _ \
| \ / | | | | / \ | | | | |_) |
| |\/| | | | |/ /\ \| | | | _ < (day 21 binary analysis)
| | | | |__| / ____ \ |__| | |_) |
|_| |_|\____/_/ \_\____/|____/
'''
Title : Microsoft Excel WOPT Record Parsing Heap Memory Corruption
Version : Excel 2002 SP3
Analysis : http://www.abysssec.com
Vendor : http://www.microsoft.com
Impact : High
Contact : shahin [at] abysssec.com , info [at] abysssec.com
Twitter : @abysssec
CVE : CVE-2010-1248
here is BA : http://www.exploit-db.com/moaub-21-microsoft-excel-wopt-record-parsing-heap-memory-corruption/
here is the PoC : https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/15065.rar (moaub-21-exploit.rar)
Exploit-DB
Microsoft Excel - HFPicture Record Parsing Remote Code Execution
exploitdb·2010-09-16·CVSS 9.3
CVE-2010-1248 [CRITICAL] Microsoft Excel - HFPicture Record Parsing Remote Code Execution
Microsoft Excel - HFPicture Record Parsing Remote Code Execution
---
'''
__ __ ____ _ _ ____
| \/ |/ __ \ /\ | | | | _ \
| \ / | | | | / \ | | | | |_) |
| |\/| | | | |/ /\ \| | | | _ < (day 16 binary anlysis)
| | | | |__| / ____ \ |__| | |_) |
|_| |_|\____/_/ \_\____/|____/
'''
Title : Microsoft Excel HFPicture Record Parsing Remote Code Execution Vulnerability
Version : Excel 2002 SP3
Analysis : http://www.abysssec.com
Vendor : http://www.microsoft.com
Impact : High
Contact : shahin [at] abysssec.com , info [at] abysssec.com
Twitter : @abysssec
CVE : CVE-2010-1248
here is BA : http://www.exploit-db.com/maoub-16-microsoft-excel-hfpicture-record-parsing-remote-code-execution-vulnerability/
here is the PoC : https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploit
No writeups or analysis indexed.
http://osvdb.org/65235http://www.securityfocus.com/archive/1/511765/100/0/threadedhttp://www.securityfocus.com/bid/40526http://www.us-cert.gov/cas/techalerts/TA10-159B.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7223http://osvdb.org/65235http://www.securityfocus.com/archive/1/511765/100/0/threadedhttp://www.securityfocus.com/bid/40526http://www.us-cert.gov/cas/techalerts/TA10-159B.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7223
2010-06-08
Published