Title: Microsoft Office Excel Malformed Description Arbitrary Code Execution
Info
Disclosure
Mar 14, 2006
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Dec 27, 2006
Description
A local overflow exists in Excel. The product fails to check the length of the Description in .xls files resulting in a buffer overflow. With a specially crafted file, an attacker can cause arbitrary code execution resulting in a loss of integrity.