Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft Excel vulnerabilities could allow remote code execution


Report ID: MS201309007
Date Published: 11 September 2013

Criticality: Important
Compromise Type: remote-code-execution information-disclosure
Compromise From: remote


Affected Product/Component:

Microsoft Excel 2003
Microsoft Excel 2007
Microsoft Excel 2010
Microsoft Excel 2013
Microsoft Office for Mac 2011
Microsoft Excel Viewer
Microsoft Office Compatibility Pack




Summary

Three vulnerabilities were reported found in Microsoft Excel, two of which could lead to remote code execution and one could lead to information disclosure.



Detailed Description

Microsoft has issued a security update for Microsoft Excel to address three reported vulnerabilities. Two vulnerabilities were caused by improper handling of objects in memory when parsing Office files, and could be exploited into allowing an attacker to execute arbitrary code. The other vulnerability was caused by improper handling of XML external entities, and could be exploited into allowing an attacker to read data from a file located on a target system.

These vulnerabilities have been resolved in the latest update by correcting the way Excel validates data when parsing Office files, and correcting the way that Excel uses XML parser. Users are recommended to install the update onto their system as a protection measure against exploit attempts.



CVE Reference

CVE-2013-1315, CVE-2013-3158, CVE-2013-3159



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-073)




Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.