Home / bulletins

MS09-009 - Critical: Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (968557) - Version:1.1

Posted on 22 April 2009

Critical

Severity Rating: Critical - Revision Note: V1.1 (April 22, 2009): Added Excel Viewer 2003 Service Pack 3 to the MBSA and SMS tables in the section, Detection and Deployment Tools and Guidance. This is an informational change only. There were no changes to the security update binaries or detection logic.Summary: This security update resolves a privately reported vulnerability and a publicly disclosed vulnerability in Microsoft Office Excel. The vulnerabilities could allow remote code execution if the user opens a specially crafted Excel file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Link

Other versions

 

TOP