CVE-2011-0978
published 2011-02-10CVE-2011-0978: Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word…
PriorityP268critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
42.56%
98.6th percentile
Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via vectors related to an axis properties record, and improper incrementing of an array index, aka "Excel Array Indexing Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | office | — | — |
| microsoft | office_compatibility_pack | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
d0cf11e0a1b11ae1 (OLE compound document magic bytes with malicious axis properties record at file offset 0x39E7)
- →Crash/exploitation occurs at EXCEL.DLL instruction 0x2f36a2fd (mov eax,dword ptr [eax+ebx*4]) when parsing the axis properties record; monitor for access violations in EXCEL.EXE at this code region. ↗
- →The malicious payload is delivered as an OLE Compound Document (CFB) file; the crafted axis properties record bytes are located at file offset 0x39E7 within the XLS stream. ↗
- →Affected process is EXCEL.EXE loading EXCEL.DLL (module base relevant to offset 2f36a2fd); endpoint detection should monitor Excel spawning child processes or shellcode execution after opening XLS files. ↗
- ·The PoC targets Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack SP2. The EXCEL.DLL code address (0x2f36a2fd) is version-specific and will differ across patch levels and ASLR states. ↗
- ·The exploit is labelled a PoC (Proof of Concept) and does not contain a working payload; the hex blob provided is a minimal reproducer to trigger the crash, not a weaponised exploit. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsofthttp://secunia.com/advisories/39122http://secunia.com/advisories/43232http://securityreason.com/securityalert/8231http://www.securitytracker.com/id?1025337http://www.us-cert.gov/cas/techalerts/TA11-102A.htmlhttp://www.vupen.com/english/advisories/2011/0940http://zerodayinitiative.com/advisories/ZDI-11-042/https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-021https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12439http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsofthttp://secunia.com/advisories/39122http://secunia.com/advisories/43232http://securityreason.com/securityalert/8231http://www.securitytracker.com/id?1025337http://www.us-cert.gov/cas/techalerts/TA11-102A.htmlhttp://www.vupen.com/english/advisories/2011/0940http://zerodayinitiative.com/advisories/ZDI-11-042/https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-021https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12439
2011-02-10
Published