cbcvebase.
CVE-2011-0104
published 2011-04-13

CVE-2011-0104: Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary…

PriorityP262critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
53.43%
98.9th percentile
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftoffice
microsoftoffice

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/35573.zip
  • Trigger is a crafted HLink record embedded within an Excel file (.xls); inspect Excel files for malformed or oversized HLink records as an indicator of exploit attempts.
  • Attack vector is social engineering to open a specially crafted Excel file; monitor for Excel process spawning unexpected child processes after opening untrusted .xls files.
  • Exploitation targets Microsoft Excel 2002 SP3 and 2003 SP3; flag execution of these specific Excel versions opening externally sourced .xls files.
  • ·Affected platforms include both Windows (Excel 2002 SP3, 2003 SP3) and Mac (Office 2004, 2008, Open XML File Format Converter); detection rules should account for both platform contexts.
  • ·Failed exploit attempts manifest as a denial-of-service (crash) rather than code execution; memory corruption crashes of Excel.exe may indicate attempted exploitation even without successful payload delivery.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.