HIGH · 9.3

CVE-2007-0028

Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary co...

Vulnerability Description

Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftExcel2000
MicrosoftOffice2000
MicrosoftExcel Viewer2003
MicrosoftWorks2004

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-0028?

CVE-2007-0028 is a vulnerability with a CVSS score of 9.3 (HIGH). Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary co...

How severe is CVE-2007-0028?

CVE-2007-0028 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0028?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Excel, Microsoft Office, Microsoft Excel Viewer, Microsoft Works.