Avis du CERT RENATER

Par défaut, cette page vous affichera les derniers messages envoyés par le CERT RENATER à la communauté. Vous pouvez affiner par année ou par type de message. Si aucun critère n'est précisé, seuls les derniers messages sont affichés
Date : Wed, 13 Apr 2011 10:30:50 +0200
Type : VULN
Sujet : CERT-Renater : 2011/VULN330 (Microsoft : Important Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution)
====================================================================                                    CERT-Renater

                         Note d'Information No. 2011/VULN330
_____________________________________________________________________

DATE                      : 13/04/2011

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running Microsoft Office version XP, 2003, 2007, 2010 2004, 2008,
                              Open XML File Format Converter for Mac, Microsoft Excel Viewer,
                              Microsoft Office Compatibility Pack for Word, Excel and PowerPoint 2007 File
                                Formats.
======================================================================
KB2489279
http://www.microsoft.com/technet/security/Bulletin/MS11-021.mspx
______________________________________________________________________

Microsoft Security Bulletin MS11-021 - Important
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2489279)
Version: 1.0

General Information

Executive Summary

This security update resolves nine privately reported vulnerabilities in
Microsoft Office. The vulnerabilities could allow remote code execution if a
user opens a specially crafted Excel file. An attacker who successfully
exploited any of these vulnerabilities could gain the same user rights as the
logged-on user. Users whose accounts are configured to have fewer user rights
on the system could be less impacted than users who operate with
administrative user rights.

This security update is rated Important for all supported editions of Microsoft
Excel 2002, Microsoft Excel 2003, Microsoft Excel 2007, Microsoft Excel 2010,
Microsoft Office 2004 for Mac, Microsoft Office 2008 for Mac, and Microsoft
Office for Mac 2011; Open XML File Format Converter for Mac; and all supported
versions of Microsoft Office Excel Viewer and Microsoft Office Compatibility
Pack. For more information, see the subsection, Affected and Non-Affected
Software, in this section.

Affected Software

Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 3
Microsoft Office 2007 Service Pack 2
Microsoft Office 2010 (32-bit editions)
Microsoft Office 2010 (64-bit editions)
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Microsoft Office for Mac 2011
Open XML File Format Converter for Mac
Microsoft Excel Viewer Service Pack 2
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File
   Formats Service Pack 2

Vulnerability Information

Excel Integer Overrun Vulnerability - CVE-2011-0097

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel Heap Overflow Vulnerability - CVE-2011-0098

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel Record Parsing WriteAV Vulnerability - CVE-2011-0101

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel Memory Corruption Vulnerability - CVE-2011-0103

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel Buffer Overwrite Vulnerability - CVE-2011-0104

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel Data Initialization Vulnerability - CVE-2011-0105

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel Array Indexing Vulnerability - CVE-2011-0978

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel Linked List Corruption Vulnerability - CVE-2011-0979

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel Dangling Pointer Vulnerability - CVE-2011-0980

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

======================================================================

           =========================================================
           Les serveurs de référence du CERT-Renater
           http://www.urec.fr/securite
           http://www.cru.fr/securite
           http://www.renater.fr
           =========================================================
           + CERT-RENATER          | tel : 01-53-94-20-44          +
           + 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
           + 75013 Paris           | email: certsvp@renater.fr     +
           =========================================================