Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."
2009-11-11T19:30:00.530
2025-04-09T00:30:58.490
Deferred
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | excel | 2002 | Yes |
Application | microsoft | excel | 2003 | Yes |
Application | microsoft | excel | 2007 | Yes |
Application | microsoft | excel | 2007 | Yes |
Application | microsoft | excel_viewer | - | Yes |
Application | microsoft | excel_viewer | - | Yes |
Application | microsoft | excel_viewer | 2003 | Yes |
Application | microsoft | office | 2004 | Yes |
Application | microsoft | office | 2008 | Yes |
Application | microsoft | open_xml_file_format_converter | * | Yes |