MS10-017: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)

This script is Copyright (C) 2010-2013 Tenable Network Security, Inc.


Synopsis :

Arbitrary code can be executed on the remote host through Microsoft
Office Excel.

Description :

The remote host contains a version of Microsoft Office Excel 2002,
Microsoft Office Excel 2003, Microsoft Office Excel 2007, Microsoft
Office Excel Viewer, or Microsoft Office Compatibility Pack that is
affected by several vulnerabilities.

If an attacker can trick a user on the affected system into opening a
specially crafted Excel file using the affected application, he may be
able to leverage this issue to execute arbitrary code subject to the
user's privileges.

See also :

http://technet.microsoft.com/en-us/security/bulletin/MS10-017

Solution :

Microsoft has released a set of patches for Office Excel 2002,
Office Excel 2003, Excel 2007, Office Excel Viewer and Office
Compatibility Pack.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.7
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 45021 ()

Bugtraq ID: 38547
38550
38551
38552
38553
38554
38555

CVE ID: CVE-2010-0257
CVE-2010-0258
CVE-2010-0260
CVE-2010-0261
CVE-2010-0262
CVE-2010-0263
CVE-2010-0264