MEDIUM · 6.6

CVE-2008-3003

Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which all...

Vulnerability Description

Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."

CVSS Score

6.6

MEDIUM

AV:L/AC:L/Au:N/C:C/I:C/A:N
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftOffice2007

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-3003?

CVE-2008-3003 is a vulnerability with a CVSS score of 6.6 (MEDIUM). Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which all...

How severe is CVE-2008-3003?

CVE-2008-3003 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-3003?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Office.