漏洞信息详情
Microsoft Excel多个远程代码执行漏洞(MS08-014)
漏洞简介
Excel是微软Office办公软件家族中的电子表格工具。
Excel导入文件时处理数据的方式、处理Style记录数据的方式、处理条件格式值和处理宏的方式存在多个代码执行漏洞,如果用户受骗打开了恶意的Excel文件,就会触发这些漏洞,导致执行任意指令。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Microsoft Office XP SP3
Microsoft Security Update for Microsoft Excel 2002 (KB946976)
http://www.microsoft.com/downloads/details.aspx?FamilyId=907f96d5-d1e9 -4471-b41c-3ac811e63038&displaylang=en
Microsoft Office 2003 SP2
Microsoft Security Update for Microsoft Office Excel 2003 (KB943985)
http://www.microsoft.com/downloads/details.aspx?FamilyId=296e5f2c-f594 -41c8-a20a-3e4c40ae3948&displaylang=en
Microsoft Office 2000 SP3
Microsoft Security Update for Microsoft Excel 2000 (KB946979)
http://www.microsoft.com/downloads/details.aspx?FamilyId=f7f90c30-1bfd -406b-a77f-612443e30185&displaylang=en
Microsoft Excel 2004 for Mac 0
Microsoft Microsoft Office 2004 for Mac 11.4.1 Update (KB949357)
http://www.microsoft.com/downloads/details.aspx?FamilyId=95DCEB37-B35F -46DB-B280-DB0F3B298AA9&displaylang=en
Microsoft Office 2004 for Mac 0
Microsoft Microsoft Office 2004 for Mac 11.4.1 Update (KB949357)
http://www.microsoft.com/downloads/details.aspx?FamilyId=95DCEB37-B35F -46DB-B280-DB0F3B298AA9&displaylang=en
Microsoft Office 2002 0
Microsoft Security Update for Microsoft Excel 2002 (KB946976)
http://www.microsoft.com/downloads/details.aspx?FamilyId=907f96d5-d1e9 -4471-b41c-3ac811e63038&displaylang=en
Microsoft Excel Viewer 2003 0
Microsoft Security Update for Microsoft Office Excel Viewer 2003 (KB943889)
http://www.microsoft.com/downloads/details.aspx?FamilyId=280bb2ac-b21a -46b5-8751-5a50fbebf107&displaylang=en
参考网址
来源: US-CERT
名称: TA08-071A
链接:http://www.us-cert.gov/cas/techalerts/TA08-071A.html
来源: BID
名称: 27305
链接:http://www.securityfocus.com/bid/27305
来源: MS
名称: MS08-014
链接:http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx
来源: www.microsoft.com
链接:http://www.microsoft.com/technet/security/advisory/947563.mspx
来源: XF
名称: microsoft-excel-unspecified-code-execution(39699)
链接:http://xforce.iss.net/xforce/xfdb/39699
来源: VUPEN
名称: ADV-2008-0846
链接:http://www.frsirt.com/english/advisories/2008/0846/references
来源: VUPEN
名称: ADV-2008-0146
链接:http://www.frsirt.com/english/advisories/2008/0146
来源: SECTRACK
名称: 1019200
链接:http://securitytracker.com/id?1019200
来源: SECUNIA
名称: 28506
链接:http://secunia.com/advisories/28506
来源: HP
名称: SSRT080028
链接:http://marc.info/?l=bugtraq&m=120585858807305&w=2
来源: oval:org.mitre.oval:def:5546
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5546
受影响实体
- Microsoft Office:2004:Mac<!--2000-1-1-->
- Microsoft Excel_viewer:2003<!--2000-1-1-->
- Microsoft Excel:2003:Sp2<!--2000-1-1-->
- Microsoft Excel:2002:Sp3<!--2000-1-1-->
- Microsoft Excel:2000:Sp3<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...