CVE-2010-1248

Microsoft Office Excel <2004 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2010-1248. PoCs published by Abysssec.

AI-analyzed exploit summary The provided content is a metadata description rather than actual exploit code. It references an external download link for the PoC, which is a common tactic in suspicious repositories. No technical details or functional exploit code are included.

Description

Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."

Exploits (2)

exploitdb SUSPICIOUS VERIFIED
by Abysssec · textdoswindows
https://www.exploit-db.com/exploits/15065

The provided content is a metadata description rather than actual exploit code. It references an external download link for the PoC, which is a common tactic in suspicious repositories. No technical details or functional exploit code are included.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Excel 2002 SP3
No auth needed
Prerequisites: None provided
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Abysssec · textdoswindows
https://www.exploit-db.com/exploits/15019

This exploit targets a vulnerability in Microsoft Excel 2002 SP3 involving improper parsing of HFPicture records, leading to remote code execution. The PoC is provided as a binary file (HFPicture_PoC.rar) and is linked to a detailed analysis by Abysssec.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Excel 2002 SP3
No auth needed
Prerequisites: Victim must open a malicious Excel file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/511765/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7223
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/40526
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-159B.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/65235

Scores

EPSS 0.2718
EPSS Percentile 97.8%

Details

CWE
CWE-94
Status published
Products (2)
microsoft/excel 2002 sp3
microsoft/office 2004
Published Jun 08, 2010
Tracked Since Feb 18, 2026