CVE-2005-4131

Microsoft Excel <2003 - RCE

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.

Exploits (1)

exploitdb WORKING POC VERIFIED
by fearwall · textdoswindows
https://www.exploit-db.com/exploits/26769

References (25)

Core 25
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/23537
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15780
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0950
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/584
Various Sources x_refsource_misc
http://news.zdnet.com/2100-1009_22-5989078.html
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/591
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19238
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-073A.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19138
Third Party Advisory, VDB Entry x_refsource_misc
http://www.osvdb.org/blog/?p=71
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015333
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/427635/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015766
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/642428
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/427698/100/0/threaded
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/news/11363
Various Sources x_refsource_misc
http://news.com.com/2061-10789_3-5988086.html

Scores

EPSS 0.6909
EPSS Percentile 98.7%

Details

Status published
Products (5)
microsoft/excel 95
microsoft/excel 97 (3 CPE variants)
microsoft/excel 2000 (4 CPE variants)
microsoft/excel 2002 (4 CPE variants)
microsoft/excel 2003 (2 CPE variants)
Published Dec 09, 2005
Tracked Since Feb 18, 2026