Microsoft Excel invalid Window2 BIFF Record Memory Corruption

Strike ID:
E12-33x01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
120
Year:
2012

Description

This strike exploits a memory corruption vulnerability in Microsoft Excel. The vulnerability is due to failure to sanitze Window2 BIFF records. This vulnerability can lead to arbitrary code execution in the context of the current user.

CVE

Bid