| CVE ID | CVE-2008-4019 |
| CVSS SCORE | |
| AFFECTED VENDORS |
Microsoft |
| AFFECTED PRODUCTS |
Office Excel |
| VULNERABILITY DETAILS |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page, or open a malicious file. The specific flaw exists when parsing Microsoft Excel documents containing a malformed REPT formula embedded inside a cell. During evaluation of this cell Excel miscalculates the size of a static buffer and copies the result of the formula into it resulting in an exploitable condition. This can result in a remote compromise of the system under the credentials of the currently logged in user. |
| ADDITIONAL DETAILS |
Microsoft has issued an update to correct this vulnerability. More details can be found at:
http://www.microsoft.com/technet/security/bulletin/MS08-057.mspx |
| DISCLOSURE TIMELINE |
|
| CREDIT | CHkr_D591 |