CVE-2011-0104

Microsoft Excel <2004 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2011-0104. PoCs published by Rodrigo Rubira Branco, Sunqiz.

AI-analyzed exploit summary The provided text describes a buffer overflow vulnerability in Microsoft Excel (CVE-2011-0104) that can be exploited via a crafted Excel file to achieve arbitrary code execution or denial-of-service. No actual exploit code is present in the snippet.

Description

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."

Exploits (2)

exploitdb WRITEUP VERIFIED
by Rodrigo Rubira Branco · textremotewindows
https://www.exploit-db.com/exploits/35573

The provided text describes a buffer overflow vulnerability in Microsoft Excel (CVE-2011-0104) that can be exploited via a crafted Excel file to achieve arbitrary code execution or denial-of-service. No actual exploit code is present in the snippet.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Excel (unspecified version)
No auth needed
Prerequisites: User interaction to open a malicious Excel file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by Sunqiz · poc
https://github.com/Sunqiz/CVE-2011-0104-reproduction

This repository contains a functional exploit PoC for CVE-2011-0104, a stack overflow vulnerability in Microsoft Excel's TOOLBARDEF record handling. The Python script generates a malicious .xlb file that triggers the vulnerability, and the accompanying writeup provides detailed technical analysis, including root cause analysis and debugging steps.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Excel 2003 SP3 (x86)
No auth needed
Prerequisites: Vulnerable version of Microsoft Excel (e.g., 2003 SP3) · Ability to deliver malicious .xlb file to target
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11767
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA11-102A.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39122
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/71761
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1025337
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/47245
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0940

Scores

EPSS 0.5343
EPSS Percentile 98.9%

Details

CWE
CWE-119
Status published
Products (5)
microsoft/excel 2002 sp3
microsoft/excel 2003 sp3
microsoft/office 2004
microsoft/office 2008
microsoft/open_xml_file_format_converter
Published Apr 13, 2011
Tracked Since Feb 18, 2026