CVE-2011-0105
published 2011-04-13CVE-2011-0105: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory…
PriorityP278critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
71.13%
99.3th percentile
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit targets EXCEL!Ordinal40+0x1a263d; a crash/AV at this offset with EAX=41414141 and stack filled with 0x41 bytes is a strong indicator of exploitation attempt. ↗
- →Post-exploitation, the Metasploit module uses 'migrate -f' as InitialAutoRunScript; monitor for Excel spawning unexpected child processes or cross-process memory injection shortly after opening an .xlb file. ↗
- →The exploit payload uses a StackAdjustment of -3500 bytes; anomalous stack pointer manipulation in EXCEL.EXE context may indicate exploitation. ↗
- →The exploit targets Windows XP SP3 specifically (Vista and 7 attempt file repair); prioritize detection on XP endpoints running Office 2007 or 2007 SP2. ↗
- ·The Metasploit module's default ExitFunction is 'process', meaning the Excel process will terminate after payload execution; this may limit dwell time for detection but also causes a visible crash. ↗
- ·The two ROP/JMP-ESP gadget addresses (0x3006A48D and 0x3006b185) are specific to Office 2007 and Office 2007 SP2 on Windows XP; these addresses will not be valid on other OS or Office versions. ↗
- ·The CVE description covers Excel 2002 SP3, Office 2004/2008 for Mac, and Open XML File Format Converter for Mac, but the Metasploit module only targets Excel 2007 on Windows XP; broader platform coverage exists beyond what the PoC implements. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpg9-x63j-3644: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized
ghsa_unreviewed·2022-05-14
CVE-2011-0105 [HIGH] CWE-119 GHSA-rpg9-x63j-3644: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
VulnCheck
Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2011·CVSS 9.3
CVE-2011-0105 [CRITICAL] Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer
Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
Affected: Microsoft Excel
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.kaspersky.co.uk/about/press-releases/old-microsoft-office-vulnerability-exploited-six-times-more-in-q2
No detection rules found.
Exploit-DB
Microsoft Excel 2007 - '.xlb' Local Buffer Overflow (MS11-021) (Metasploit)
exploitdb·2011-11-05
CVE-2011-0105 Microsoft Excel 2007 - '.xlb' Local Buffer Overflow (MS11-021) (Metasploit)
Microsoft Excel 2007 - '.xlb' Local Buffer Overflow (MS11-021) (Metasploit)
---
##
# $Id: ms11_021_xlb_bof.rb 14172 2011-11-06 20:16:34Z sinn3r $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 "MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow",
'Description' => %q{
This module exploits a vulnerability found in Excel of Microsoft Office 2007.
By supplying a malformed .xlb file, an attacker can control the content (source)
of a memcpy routine, and the number of bytes to copy, therefore causing a stack-
based buffer overflow. This res
Metasploit
MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
metasploit
MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
This module exploits a vulnerability found in Excel of Microsoft Office 2007. By supplying a malformed .xlb file, an attacker can control the content (source) of a memcpy routine, and the number of bytes to copy, therefore causing a stack- based buffer overflow. This results in arbitrary code execution under the context of the user.
Zscaler
Zscaler found Multiple Security Vulnerabilities | 04-12-2011
blogs_zscaler·CVSS 9.3
[CRITICAL] Zscaler found Multiple Security Vulnerabilities | 04-12-2011
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2011-2262 mysql: Unspecified vulnerability allows remote attackers to affect availability
bugzilla·2012-01-22·CVSS 5.0
CVE-2011-2262 [MEDIUM] CVE-2011-2262 mysql: Unspecified vulnerability allows remote attackers to affect availability
CVE-2011-2262 mysql: Unspecified vulnerability allows remote attackers to affect availability
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-2262 to the following vulnerability:
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote attackers to affect availability via unknown vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2262
Discussion:
Created mysql tracking bugs for this issue
Affects: fedora-all [bug 783828]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:0105 https://rhn.redhat.com/errata/RHSA-2012-0105.html
---
mysql-5.5.20-1.fc16 has been pushe
http://secunia.com/advisories/39122http://www.securitytracker.com/id?1025337http://www.us-cert.gov/cas/techalerts/TA11-102A.htmlhttp://www.vupen.com/english/advisories/2011/0940https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-021https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12618http://secunia.com/advisories/39122http://www.securitytracker.com/id?1025337http://www.us-cert.gov/cas/techalerts/TA11-102A.htmlhttp://www.vupen.com/english/advisories/2011/0940https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-021https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12618
2011-04-13
Published
Exploited in the wild