MS.Excel.Malformed.Palette.Record.Code.Execution

description-logoDescription

This indicates an attempt to exploit a heap based buffer overflow vulnerability in Microsoft Excel.
The vulnerability can be exploited via a malformed Excel file with a "PALETTE" record that contains a large number of entries. As a result a remote attacker can cause the execution of arbitrary code on a vulnerable system with the privileges of the victim.

affected-products-logoAffected Products

Microsoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 2
Microsoft Office Excel Viewer 2003
Microsoft Excel 2002
Microsoft Excel 2000
Microsoft Excel 2003
Microsoft Works Suite 2004
Microsoft Works Suite 2005
Microsoft Office 2004 for Mac
Microsoft Office v. X for Mac

Impact logoImpact

System compromise: remote code execution.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)