CERT-In Vulnerability Note
CIVN-2011-0189
Microsoft Excel Remote Code Execution Vulnerability
Original Issue Date:December 14, 2011
Severity Rating: HIGH
Component Affected
- Microsoft Office Suites and Components
- Microsoft Office 2003 Service Pack 3
- Microsoft Office for Mac
- Microsoft Office 2004 for Mac
Overview
A vulnerability has been reported in Microsoft Excel which could allow a remote attacker to take complete control of the affected system.
Description
This vulnerability is caused due to improper validation of records in Microsoft Office Excel documents. An unauthenticated, remote attacker could exploit this vulnerability by enticing users to open a malicious crafted document. Memory corruption condition could occurs while processing the crafted malicious document. Successful exploitation of this vulnerability could allow attacker to execute arbitrary code on the system with the privileges of currently logged-in user.
Workaround
- Use Limited privileged user
- Protect yourself against social engineering attacks
- Do not open Office files that you receive from untrusted sources or that you receive unexpectedly from trusted sources
- Set Office File Validation to disable the opening of files that fail validation in Excel 2003
- Use Microsoft Office File Block policy to block the opening of Office 2003 and earlier documents from unknown or untrusted sources and locations
- Use the Microsoft Office Isolated Conversion Environment (MOICE) when opening files from unknown or untrusted sources
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS11-096
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms11-096
References
SecurityFocus
http://www.securityfocus.com/bid/50954
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=24711
CVE Name
CVE-2011-3403
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|