CVE-2012-5672

Microsoft Excel and Excel Viewer - Denial of Service via Crafted Spreadsheet File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5672. PoCs published by Jean Pascal Pereira.

AI-analyzed exploit summary This Perl script generates a crafted Excel file that triggers a read access violation in Microsoft Office Excel, leading to a denial-of-service (DoS) condition. The PoC exploits CVE-2012-5672 by manipulating specific file structures to cause an access violation.

Description

Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jean Pascal Pereira · perldoswindows
https://www.exploit-db.com/exploits/37980

This Perl script generates a crafted Excel file that triggers a read access violation in Microsoft Office Excel, leading to a denial-of-service (DoS) condition. The PoC exploits CVE-2012-5672 by manipulating specific file structures to cause an access violation.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Excel 2007 and Microsoft Excel Reader 12
No auth needed
Prerequisites: Ability to deliver a crafted Excel file to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/524379

Scores

EPSS 0.1603
EPSS Percentile 95.0%

Details

Status published
Products (3)
microsoft/excel 2007
microsoft/excel_viewer
microsoft/office 2007
Published Oct 25, 2012
Tracked Since Feb 18, 2026