Home / bulletins

MS08-043 – Critical: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (954066) - Version:1.2

Posted on 20 August 2008

There is an newer version: MS08-043 - Version: 1.3

Critical

Severity Rating: Critical - Revision Note: V1.2 (August 20, 2008): Added note to the Affected Software table and a FAQ entry to clarify that this update applies to servers that have Excel Services installed, such as the default configuration of Microsoft Office SharePoint Server 2007 Enterprise and Microsoft Office SharePoint Server 2007 For Internet Sites. Microsoft Office SharePoint Server 2007 Standard does not include Excel Services. Summary: This security update resolves four privately reported vulnerabilities in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Link

Other versions

 

TOP