CVE-2011-0980

Microsoft Excel 2002/2003, Office 2004/2008 for Mac - RCE via Office Art Object Parsing

Title source: llm
STIX 2.1

Description

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."

References (9)

Core 9
Core References
Third Party Advisory x_refsource_misc
http://zerodayinitiative.com/advisories/ZDI-11-040/
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA11-102A.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39122
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1025337
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43210
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0940
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12018

Scores

EPSS 0.2637
EPSS Percentile 97.8%

Details

CWE
CWE-264
Status published
Products (5)
microsoft/excel 2002 sp3
microsoft/excel 2003 (2 CPE variants)
microsoft/office 2004
microsoft/office 2008
microsoft/open_xml_file_format_converter
Published Feb 10, 2011
Tracked Since Feb 18, 2026