CVE-2005-4131
CVSS6.8
发布时间 :2005-12-09 06:03:00
修订时间 :2011-04-15 00:00:00
NMCOPS    

[原文]Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.


[CNNVD]Microsoft Excel畸形命名区域内存破坏漏洞(CNNVD-200512-170)

        Microsoft Excel是Office产品套件中的电子表格和分析程序。
        Microsoft Excel中存在安全漏洞,攻击者可能利用此漏洞在机器上执行指令。如果能够通过Excel .xls文件的数据字段向"msvcrt.memmove()"传送很大的值的话,就可能导致内存破坏,执行任意代码。
        

- CVSS (基础分值)

CVSS分值: 6.8 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: PARTIAL [可能会导致系统文件被修改]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: MEDIUM [漏洞利用存在一定的访问条件]
攻击向量: NETWORK [攻击者不需要获取内网访问权或本地访问权]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/a:microsoft:excel:97:sr1Microsoft Excel 97 SR1
cpe:/a:microsoft:excel:2002:sp1Microsoft Excel 2002 SP1
cpe:/a:microsoft:excel:2002Microsoft Excel 2002
cpe:/a:microsoft:excel:2003Microsoft Excel 2003
cpe:/a:microsoft:excel:2000Microsoft Excel 2000
cpe:/a:microsoft:excel:2003:sp1Microsoft Excel 2003 SP1
cpe:/a:microsoft:excel:97:sr2Microsoft Excel 97 SR2
cpe:/a:microsoft:excel:2000:sp3Microsoft Excel 2000 Service Pack 3
cpe:/a:microsoft:excel:2000:sp2Microsoft Excel 2000 SP2
cpe:/a:microsoft:excel:2002:sp2Microsoft Excel 2002 SP2
cpe:/a:microsoft:excel:2000:sr1Microsoft Excel 2000 SR1
cpe:/a:microsoft:excel:2002:sp3Microsoft Office Excel 2002 Service Pack 3
cpe:/a:microsoft:excel:95Microsoft Excel 95
cpe:/a:microsoft:excel:97Microsoft Excel 97

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4131
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-4131
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200512-170
(官方数据源) CNNVD

- 其它链接及资源

http://www.us-cert.gov/cas/techalerts/TA06-073A.html
(UNKNOWN)  CERT  TA06-073A
http://www.kb.cert.org/vuls/id/642428
(UNKNOWN)  CERT-VN  VU#642428
http://www.securityfocus.com/bid/15780
(PATCH)  BID  15780
http://xforce.iss.net/xforce/xfdb/23537
(UNKNOWN)  XF  excel-msvcrt-memmove-bo(23537)
http://www.vupen.com/english/advisories/2006/0950
(VENDOR_ADVISORY)  VUPEN  ADV-2006-0950
http://www.theregister.co.uk/2005/12/10/ebay_pulls_excel_vulnerability_auction/
(UNKNOWN)  MISC  http://www.theregister.co.uk/2005/12/10/ebay_pulls_excel_vulnerability_auction/
http://www.theage.com.au/news/breaking/excel-flaw-up-for-sale-on-ebay/2005/12/09/1134086783318.html
(UNKNOWN)  MISC  http://www.theage.com.au/news/breaking/excel-flaw-up-for-sale-on-ebay/2005/12/09/1134086783318.html
http://www.securityfocus.com/news/11363
(UNKNOWN)  MISC  http://www.securityfocus.com/news/11363
http://www.securityfocus.com/archive/1/archive/1/427698/100/0/threaded
(UNKNOWN)  BUGTRAQ  20060315 [HV-HIGH] Microsoft Excel Named Range Arbitrary Code Execution
http://www.securityfocus.com/archive/1/archive/1/427635/100/0/threaded
(UNKNOWN)  BUGTRAQ  20060314 High Risk Vulnerability in Microsoft Excel
http://www.osvdb.org/blog/?p=71
(UNKNOWN)  MISC  http://www.osvdb.org/blog/?p=71
http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx
(UNKNOWN)  MS  MS06-012
http://www.eweek.com/article2/0,1759,1899697,00.asp?kc=EWRSS03129TX1K0000614
(UNKNOWN)  MISC  http://www.eweek.com/article2/0,1759,1899697,00.asp?kc=EWRSS03129TX1K0000614
http://www.dicks-blog.com/archives/2005/12/08/excel-vulnerability-for-sale/
(UNKNOWN)  MISC  http://www.dicks-blog.com/archives/2005/12/08/excel-vulnerability-for-sale/
http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm
(UNKNOWN)  CONFIRM  http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm
http://securitytracker.com/id?1015766
(UNKNOWN)  SECTRACK  1015766
http://securitytracker.com/id?1015333
(UNKNOWN)  SECTRACK  1015333
http://securityreason.com/securityalert/591
(UNKNOWN)  SREASON  591
http://securityreason.com/securityalert/584
(UNKNOWN)  SREASON  584
http://secunia.com/advisories/19238
(VENDOR_ADVISORY)  SECUNIA  19238
http://secunia.com/advisories/19138
(VENDOR_ADVISORY)  SECUNIA  19138
http://news.zdnet.com/2100-1009_22-5989078.html
(UNKNOWN)  MISC  http://news.zdnet.com/2100-1009_22-5989078.html
http://news.com.com/2061-10789_3-5988086.html
(UNKNOWN)  MISC  http://news.com.com/2061-10789_3-5988086.html
http://informationweek.com/story/showArticle.jhtml?articleID=174910198
(UNKNOWN)  MISC  http://informationweek.com/story/showArticle.jhtml?articleID=174910198
http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=7203336538
(UNKNOWN)  MISC  http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=7203336538

- 漏洞信息

Microsoft Excel畸形命名区域内存破坏漏洞
中危 输入验证
2005-12-09 00:00:00 2007-01-04 00:00:00
远程※本地  
        Microsoft Excel是Office产品套件中的电子表格和分析程序。
        Microsoft Excel中存在安全漏洞,攻击者可能利用此漏洞在机器上执行指令。如果能够通过Excel .xls文件的数据字段向"msvcrt.memmove()"传送很大的值的话,就可能导致内存破坏,执行任意代码。
        

- 公告与补丁

        目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
        http://www.microsoft.com/technet/security/Bulletin/MS06-012.mspx#E4EAE

- 漏洞信息 (F44667)

HexView Security Advisory 2006-03-14.1 (PacketStormID:F44667)
2006-03-15 00:00:00
HexView  hexview.com
advisory
windows,2k,xp
CVE-2005-4131
[点击下载]

A vulnerability exists in Microsoft Excel which can be exploited to run a code of attacker's choice on user's PC. Sufficient data validation is not performed when parsing "Named Range" definitions in the document file, which makes it possible to produce a negative 32-bit value that is later used as a length parameter for the msvcrt.memmove() function. As a result, a large chunk of memory is copied overwriting critical memory ranges, including the stack space. All tests were performed using Microsoft Excel 2003 (11.6560.6568) on Windows XP and Windows 2000 Pro platforms. It is likely that all MS Excel products are vulnerable.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Microsoft Excel Named Range Arbitrary Code Execution

Classification:
===============
Level: low-med-[HIGH]-crit
ID: HEXVIEW*2006*03*14*1
URL: http://www.hexview.com/docs/20060314-1.txt

References:
===============
[Originally published by fearwall on eBay]
CVE: CVE-2005-4131
OVSDB: 21568
BUGTRAQ: 15780
MSFT: MS06-012

Misc References:
================
http://www.hexview.com/msva.html
http://www.eweek.com/article2/0,1759,1899697,00.asp?kc=EWRSS03129TX1K0000614
http://news.zdnet.com/2100-1009_22-5989078.html
http://informationweek.com/story/showArticle.jhtml?articleID=174910198
http://www.theage.com.au/news/breaking/excel-flaw-up-for-sale-on-ebay/2005/12/09/1134086783318.html
http://www.securityfocus.com/news/11363
http://news.com.com/2061-10789_3-5988086.html
http://www.theregister.co.uk/2005/12/10/ebay_pulls_excel_vulnerability_auction/
http://www.securityfocus.com/bid/15780
http://securitytracker.com/id?1015333
http://xforce.iss.net/xforce/xfdb/23537

Overview:
=========
A vulnerability exists in Microsoft Excel which can be exploited to run
a code of attacker's choice on user's PC.

Affected products:
==================
All tests were performed using Microsoft Excel 2003 (11.6560.6568) on
Windows XP and Windows 2000 Pro platforms. It is likely that all MS Excel
products are vulnerable.

Cause and Effect:
=================
Sufficient data validation is not performed when parsing "Named Range" 
definitions in the document file, which makes possible to produce a negative
32-bit value that is later used as a length parameter for msvcrt.memmove()
function. As a result, a large chunk of memory is copied overwriting
critical memory ranges, including the stack space. 

Demonstration:
==============
Below is a fragment of the empty XLS file containing a named range definition
"Sheet1!TEST1". Two bytes marked with asterisks cause exception to occur
when set to 0xFF.

00000720  00 80 00 ff 93 02 04 00  14 80 05 ff 60 01 02 00  |............`...|
00000730  00 00 85 00 0e 00 ba 05  00 00 00 00 06 00 53 68  |..............Sh|
00000740  65 65 74 31 8c 00 04 00  01 00 01 00 ae 01 04 00  |eet1............|
00000750  01 00 01 04 17 00 08 00  01 00 00 00 00 00 00 00  |................|
00000760  18 00 1b 00 00 00 00 05  07 ** ** 00 00 00 00 00  |................|
00000770  00 00 00 54 45 53 54 31  3a 00 00 00 00 00 00 c1  |...TEST1:.......|
00000780  01 08 00 c1 01 00 00 22  be 01 00 fc 00 08 00 00  |......."........|
00000790  00 00 00 00 00 00 00 ff  00 02 00 08 00 63 08 15  |.............c..|

Vendor Status:
==============
Microsoft was notified on December 6th, 2006. The issue has been investigated
and the patch is currently available from Microsoft (MS06-012).

You may want to look at:
========================

Microsoft Office 2003 helps protect and control vital business information
using IRM (Information Rights Management) capabilities. IRM prevents or
limits documents from being used in unintended ways, giving organizations
and information workers greater control of their sensitive information.
- ---
OpenOffice is a full-featured office suite compatible with leading office
products. Thousands of developers around the world collaborate their
efforts to create the best possible office suite that all can use.
OpenOffice is free and secure alternative office suite.
Learn more at http://www.openoffice.org

About HexView:
==============
HexView has been contributing to online security-related lists for over a
decade. The scope of our expertize spreads over Windows, Linux, Sun, MacOS
platforms,network applications, and embedded devices. We also offer a variety
of consulting services. For more information visit http://www.hexview.com

Distribution:
=============
This document may be freely distributed through any channels as long as
the contents are kept unmodified. Commercial use of the information in
the document is not allowed without written permission from HexView
signed by our pgp key. Please direct all questions to vtalk@hexview.com

Feedback and comments:
======================
Feedback and questions about this disclosure are welcome at vtalk@hexview.com

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFEF2bbDPV1+KQrDqQRAkM2AKC004V+S1q7zAeWAC8kB5YCJulmugCdG13O
6bDc0BwT9HMFJSOtKdGOWsw=
=cwmh
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
    

- 漏洞信息 (F44663)

Technical Cyber Security Alert 2006-73A (PacketStormID:F44663)
2006-03-15 00:00:00
CERT,US-CERT  us-cert.gov
advisory,remote,denial of service,arbitrary,vulnerability
CVE-2005-4131,CVE-2006-0009,CVE-2006-0028,CVE-2006-0029,CVE-2006-0030,CVE-2006-0031
[点击下载]

Technical Cyber Security Alert TA06-073A - Microsoft has released updates that address critical vulnerabilities in Microsoft Office and Excel. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



                        National Cyber Alert System

                Technical Cyber Security Alert TA06-073A


Microsoft Office and Excel Vulnerabilities

   Original release date: March 14, 2006
   Last revised: --
   Source: US-CERT


Systems Affected

     * Microsoft Office for Windows and Mac OS X
     * Microsoft Excel for Windows and Mac OS X
     * Microsoft Works Suite for Windows

   For more complete information, refer to the Microsoft Security
   Bulletin Summary for March 2006.


Overview

   Microsoft has released updates that address critical vulnerabilities
   in Microsoft Office and Excel. Exploitation of these vulnerabilities
   could allow a remote, unauthenticated attacker to execute arbitrary
   code or cause a denial of service on a vulnerable system.


I. Description

   Microsoft Security Bulletin Summary for March 2006 addresses
   vulnerabilities in Microsoft Office and Excel. Further information is
   available in the following US-CERT Vulnerability Notes:

   VU#339878 - Microsoft Excel malformed parsing format file memory
   corruption vulnerability 

   Microsoft Excel contains a memory corruption vulnerability. This
   vulnerability may allow a remote attacker to execute arbitrary code on
   a vulnerable system.
   (CVE-2006-0028)

   VU#104302 - Microsoft Excel malformed record memory corruption
   vulnerability 

   Microsoft Excel fails to properly validate records. This vulnerability
   may allow a remote attacker to execute arbitrary code on a vulnerable
   system.
   (CVE-2006-0031)

   VU#123222 - Microsoft Excel malformed graphic memory corruption
   vulnerability 

   Microsoft Excel fails to properly validate graphics. This
   vulnerability may allow a remote attacker to execute arbitrary code on
   a vulnerable system.
   (CVE-2006-0030)

   VU#235774 - Microsoft Excel malformed description memory corruption
   vulnerability 

   Microsoft Excel fails to properly validate the description field. This
   vulnerability may allow a remote attacker to execute arbitrary code on
   a vulnerable system.
   (CVE-2006-0029)

   VU#642428 - Microsoft Excel fails to properly perform range validation
   when parsing document files 

   Microsoft Excel contains an error in range validation, which may allow
   a remote unauthenticated, attacker to execute arbitrary code on a
   vulnerable system.
   (CVE-2005-4131)

   VU#682820 - Microsoft Office routing slip buffer overflow 

   Microsoft Office contains a buffer overflow in the parsing of routing
   slips, which may allow an attacker to execute arbitrary code on a
   vulnerable system.
   (CVE-2006-0009)


II. Impact

   A remote, unauthenticated attacker could execute arbitrary code with
   the privileges of the user. If the user is logged on with
   administrative privileges, the attacker could take complete control of
   an affected system. An attacker may also be able to cause a denial of
   service.


III. Solution

Apply Updates

   Microsoft has provided the updates for these vulnerabilities in the
   Security Bulletins and on the Microsoft Update site.


Workarounds

   Please see the following US-CERT Vulnerability Notes for workarounds.


Appendix A. References

     * Microsoft Security Bulletin Summary for March 2006 -
       <http://www.microsoft.com/technet/security/bulletin/ms06-mar.mspx>

     * US-CERT Vulnerability Note VU#339878 -
       <http://www.kb.cert.org/vuls/id/339878>

     * US-CERT Vulnerability Note VU#104302 -
       <http://www.kb.cert.org/vuls/id/104302>

     * US-CERT Vulnerability Note VU#123222 -
       <http://www.kb.cert.org/vuls/id/123222>

     * US-CERT Vulnerability Note VU#235774 -
       <http://www.kb.cert.org/vuls/id/235774>

     * US-CERT Vulnerability Note VU#642428 -
       <http://www.kb.cert.org/vuls/id/642428>

     * US-CERT Vulnerability Note VU#682820 -
       <http://www.kb.cert.org/vuls/id/682820>

     * CVE-2005-4131 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4131>

     * CVE-2006-0009 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0009>

     * CVE-2006-0028 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0028>

     * CVE-2006-0029 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0029>

     * CVE-2006-0030 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0030>

     * CVE-2006-0031 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031>

     * Microsoft Update - <https://update.microsoft.com/microsoftupdate>


 ____________________________________________________________________
 
   The most recent version of this document can be found at:

     <http://www.us-cert.gov/cas/techalerts/TA06-073A.html>
 ____________________________________________________________________

   Feedback can be directed to US-CERT Technical Staff. Please send
   email to <cert@cert.org> with "TA06-073A Feedback VU#339878" in the
   subject.
 ____________________________________________________________________

   For instructions on subscribing to or unsubscribing from this
   mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
 ____________________________________________________________________

   Produced 2006 by US-CERT, a government organization.

   Terms of use:

     <http://www.us-cert.gov/legal.html>
 ____________________________________________________________________


Revision History

   March 14, 2006: Initial release
  
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iQEVAwUBRBdHxH0pj593lg50AQKjmwgA09ePMKZtjsxkwWaWMSFxtqGZaeV1hHby
LBApam/YAuNpmLZKzwz36quzlbceDcSeBQKKbvgqhi/Cm4Sjsywczay0agHsdXiv
dzwQCAeE0+5JA2kidsdQV9u+X866hfDq63oXy3nef/x1RPOBvNSOb8FnG1yvMCwn
965R6SUbtrA/4HRcEmVH+8dciSnARh90rcIPN6EorC7mCdXykk2YDs0MX8nuT+fl
HeHn06kvTkmJbRNZ/xq7LyGIVeuQ7Xqv1fCiqywNdJUxHg1YPmBIPqfY3e6dcqE1
rS6ithE6u9GlDMTYbTLhL3+JGE4IiIRuZL10z37x+w07AHSFuTHfWQ==
=3xcR
-----END PGP SIGNATURE-----
    

- 漏洞信息

21568
Microsoft Excel xls Processing msvcrt.memmove() Function Malformed Range Overflow
Input Manipulation
Loss of Integrity

- 漏洞描述

Unknown or Incomplete

- 时间线

2005-12-08 2005-12-06
Unknow Unknow

- 解决方案

Unknown or Incomplete

- 相关参考

- 漏洞作者

Unknown or Incomplete

- 漏洞信息

Microsoft Excel Malformed Range Memory Corruption Vulnerability
Input Validation Error 15780
Yes Yes
2005-12-08 12:00:00 2006-04-06 08:18:00
Discovery is credited to 'fearwall'. Microsoft also credits FelicioX and Peter Winter-Smith for the discovery of this vulnerability.

- 受影响的程序版本

Nortel Networks Optivity Telephony Manager (OTM)
Nortel Networks MCS 5200 3.0
Nortel Networks MCS 5100 3.0
Nortel Networks IP softphone 2050
Nortel Networks Enterprise Network Management System
Microsoft Excel x for Mac 0
Microsoft Excel Viewer 2003 0
+ Microsoft Office 2003 SP1
+ Microsoft Office 2003 SP1
+ Microsoft Office 2003 SP1
Microsoft Excel 97 SR2
Microsoft Excel 97 SR1
Microsoft Excel 97
+ Microsoft Office 97
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Microsoft Excel 95
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Microsoft Excel 2004 for Mac 0
Microsoft Excel 2003 SP1
+ Microsoft Office 2003 SP1
Microsoft Excel 2003
+ Microsoft Office 2003 0
Microsoft Excel 2002 SP3
+ Microsoft Office XP SP3
Microsoft Excel 2002 SP2
+ Microsoft Office XP SP2
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home SP1
- Microsoft Windows XP Home
- Microsoft Windows XP Professional SP1
- Microsoft Windows XP Professional
Microsoft Excel 2002 SP1
+ Microsoft Office XP SP1
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Terminal Services SP2
- Microsoft Windows 2000 Terminal Services SP1
- Microsoft Windows 2000 Terminal Services
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
- Microsoft Windows XP Professional
Microsoft Excel 2002
+ Microsoft Office XP
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95 SR2
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0
Microsoft Excel 2000 SR1
+ Microsoft Office 2000 SP1
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Terminal Services SP2
- Microsoft Windows 2000 Terminal Services SP1
- Microsoft Windows 2000 Terminal Services
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
Microsoft Excel 2000 SP3
+ Microsoft Office 2000 SP3
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home SP1
- Microsoft Windows XP Home
- Microsoft Windows XP Professional SP1
- Microsoft Windows XP Professional
Microsoft Excel 2000 SP2
+ Microsoft Office 2000 SP2
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Terminal Services SP2
- Microsoft Windows 2000 Terminal Services SP1
- Microsoft Windows 2000 Terminal Services
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
Microsoft Excel 2000
+ Microsoft Office 2000
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP6
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0
Avaya Modular Messaging (MAS) 3.0

- 漏洞讨论

Microsoft Excel is susceptible to a remote code-execution vulnerability. This issue was originally disclosed through an eBay auction that has since been terminated.

This issue is due to the application's failure to properly bounds-check user-supplied input data in the 'Named Range' definition in Excel data files. This results in the corruption of critical memory sections, allowing code execution.

- 漏洞利用

An exploit reportedly exists. The discoverer has stated that the exploit will not be made available.

The following is a proof-of-concept example segment of an Excel data file. The '*' characters represent the location of the affected value that triggers this issue. Setting these locations to '0xFF' will crash the application.

00000720 00 80 00 ff 93 02 04 00 14 80 05 ff 60 01 02 00 |............`...|
00000730 00 00 85 00 0e 00 ba 05 00 00 00 00 06 00 53 68 |..............Sh|
00000740 65 65 74 31 8c 00 04 00 01 00 01 00 ae 01 04 00 |eet1............|
00000750 01 00 01 04 17 00 08 00 01 00 00 00 00 00 00 00 |................|
00000760 18 00 1b 00 00 00 00 05 07 ** ** 00 00 00 00 00 |................|
00000770 00 00 00 54 45 53 54 31 3a 00 00 00 00 00 00 c1 |...TEST1:.......|
00000780 01 08 00 c1 01 00 00 22 be 01 00 fc 00 08 00 00 |......."........|
00000790 00 00 00 00 00 00 00 ff 00 02 00 08 00 63 08 15 |.............c..|

- 解决方案

Microsoft has released fixes to address this vulnerability in supported versions of the affected software.

Please see the referenced vendor advisories for further information.


Microsoft Excel 2000 SR1

Microsoft Excel x for Mac 0

Microsoft Excel 2003 SP1

Microsoft Excel 2002 SP2

Microsoft Excel 2000 SP2

Microsoft Excel 2003

Microsoft Excel 2004 for Mac 0

Microsoft Excel 2002 SP3

Microsoft Excel 2002 SP1

Microsoft Excel 2000

Microsoft Excel 2002

Microsoft Excel 2000 SP3

Microsoft Excel Viewer 2003 0

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站