ID:538 - Exploit for Remote code execution in Microsoft products - CVE-2008-0116

 
Main Vulnerability Database Exploits ID:538 - Exploit for Remote code execution in Microsoft products - CVE-2008-0116

ID:538 - Exploit for Remote code execution in Microsoft products - CVE-2008-0116

Published: March 18, 2020


Vulnerability identifier: #VU1263
Vulnerability risk: High
CVE-ID: CVE-2008-0116
CWE-ID: CWE-119
Exploitation vector: Remote access
Vulnerable software:
Microsoft Office for macOS
Microsoft Excel
Excel Viewer

Link to public exploit:


Vulnerability description

The vulnerability alows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to a boundary error when loading application data into memory. A remote attacker can create a specially crafted Excel file with rich text values, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system with privileges of the current user.

Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.

Remediation

Install update from vendor's website:

Excel 2000 Service Pack 3:
https://www.microsoft.com/downloads/details.aspx?FamilyId=f7f90c30-1bfd-406b-a77f-612443e30185
Excel 2002 Service Pack 3:
https://www.microsoft.com/downloads/details.aspx?FamilyId=907f96d5-d1e9-4471-b41c-3ac811e63038
Excel 2003 Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyId=296e5f2c-f594-41c8-a20a-3e4c40ae3948
Microsoft Office Excel Viewer 2003:
https://www.microsoft.com/downloads/details.aspx?FamilyId=280bb2ac-b21a-46b5-8751-5a50fbebf107
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats:
https://www.microsoft.com/downloads/details.aspx?FamilyId=e9251d71-9098-4125-ae91-7d4c83ea58ad
Microsoft Office 2004 for Mac:
https://www.microsoft.com/downloads/details.aspx?FamilyId=95DCEB37-B35F-46DB-B280-DB0F3B298AA9
Microsoft Office 2008 for Mac:
https://www.microsoft.com/downloads/details.aspx?FamilyId=8FE8C32A-6D7A-482B-97C6-42562F089EE4