CVE-2008-0116

Microsoft Excel - Code Injection

Title source: rule

Description

Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."

Exploits (1)

exploitdb SUSPICIOUS
localwindows
https://www.exploit-db.com/exploits/5287

Scores

EPSS 0.7438
EPSS Percentile 98.9%

Details

CWE
CWE-20 CWE-94
Status published
Products (7)
microsoft/excel 2000 sp3
microsoft/excel 2002 sp3
microsoft/excel 2003 sp2
microsoft/excel_viewer 2003
microsoft/office 2004
microsoft/office 2008
microsoft/office_compatibility_pack_for_word_excel_ppt_2007
Published Mar 11, 2008
Tracked Since Feb 18, 2026