>> Microsoft Office Document Handling Client-Side Command Execution Vulnerability
Title : Microsoft Office Document Handling Client-Side Command Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-0463 CVE ID : CVE-2007-0671
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-02-03
Technical Description
A vulnerability has been identified in Microsoft Office, which could be exploited by attackers to take complete control of an affected system. This issue is due to a memory corruption error when handling documents containing a malformed string, which could be exploited by attackers to execute arbitrary commands by tricking a user into opening a specially crafted document.
This vulnerability is being exploited in the wild. Excel is the current attack vector.