CVE Vulnerabilities

CVE-2009-0561

Published: Jun 10, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Microsoft Office SharePoint Server 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via an Excel file with a Shared String Table (SST) record with a numeric field that specifies an invalid number of unique strings, which triggers a heap-based buffer overflow, aka Record Integer Overflow Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
OfficeMicrosoft2004 (including)2004 (including)
OfficeMicrosoft2008 (including)2008 (including)
OfficeMicrosoftxp-sp3 (including)xp-sp3 (including)
Office_compatibility_pack_for_word_excel_ppt_2007Microsoft**
Office_excelMicrosoft2000-sp3 (including)2000-sp3 (including)
Office_excelMicrosoft2003-sp3 (including)2003-sp3 (including)
Office_excelMicrosoft2007-sp1 (including)2007-sp1 (including)
Office_excelMicrosoft2007-sp2 (including)2007-sp2 (including)
Office_excel_viewerMicrosoft**
Office_excel_viewerMicrosoft2003-sp3 (including)2003-sp3 (including)
Office_sharepoint_serverMicrosoft2007-sp1 (including)2007-sp1 (including)
Office_sharepoint_serverMicrosoft2007-sp2 (including)2007-sp2 (including)
Open_xml_file_format_converterMicrosoft**

References