MS10-038: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452)

This script is Copyright (C) 2010-2013 Tenable Network Security, Inc.


Synopsis :

Arbitrary code can be executed on the remote host through Microsoft
Office Excel.

Description :

The remote host contains a version of Microsoft Office Excel 2002,
Microsoft Office Excel 2003, Microsoft Office Excel 2007, Microsoft
Office Excel Viewer, or Microsoft Office Compatibility Pack that is
affected by several vulnerabilities.

If an attacker can trick a user on the affected system into opening a
specially crafted Excel file using the affected application, he may be
able to leverage these issues to execute arbitrary code subject to the
user's privileges.

See also :

http://technet.microsoft.com/en-us/security/bulletin/MS10-038

Solution :

Microsoft has released a set of patches for Office Excel 2002,
Office Excel 2003, Excel 2007, Office Excel Viewer and Office
Compatibility Pack.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.3
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true