CVE-2011-0978
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 43%
from disclosure to weapon78 days
Published on NVDFeb 10
1st PoC+78d
exploitation probability
43%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via vectors related to an axis properties record, and improper incrementing of an array index, aka "Excel Array Indexing Vulnerability."
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/17227⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsofthttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-021http://secunia.com/advisories/39122http://secunia.com/advisories/43232http://securityreason.com/securityalert/8231https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12439http://www.securitytracker.com/id?1025337http://www.us-cert.gov/cas/techalerts/TA11-102A.htmlhttp://www.vupen.com/english/advisories/2011/0940http://zerodayinitiative.com/advisories/ZDI-11-042/