>> Microsoft Office Excel File Handling Memory Corruption Vulnerabilities (MS07-036)
Title : Microsoft Office Excel File Handling Memory Corruption Vulnerabilities (MS07-036) VUPEN ID : VUPEN/ADV-2007-2478 CVE ID : CVE-2007-1756 - CVE-2007-3029 - CVE-2007-3030
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-10
Technical Description
Multiple vulnerabilities have been identified in Microsoft Office, which could be exploited by attackers to take complete control of an affected system.
The first issue is caused by a memory corruption error when processing version information, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted Excel file.
The second vulnerability is caused by a memory corruption error when processing the number of active worksheets, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted Excel file.
The third issue is caused by a memory corruption error when denoting the start of a Workspace designation, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted Excel file.