52695 : Microsoft Office Excel Crafted Document Invalid Object Reference Unspecified Code Execution
Printer | http://osvdb.org/52695 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
9 684 over 2 years ago 12 months ago 10 times 35%

This Entry needs help! It is only 35% Complete. Click the edit link above to add more information.

Contributing is fast and easy, and benefits the entire security community.

Timeline

Disclosure Date Vendor Solution Date
2009-02-23 2009-04-14

Keywords

Trojan.Mdropper.AC

Description

<em style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0238" target="_blank">CVE</a>)</em> : Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.

Classification

Location: Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Commercial
Disclosure: Vendor Verified, Uncoordinated Disclosure, Discovered in the Wild

Products

Unknown or Incomplete

References

Tools & Filters

36147 50061

Credit

CVSSv2 Score

CVSSv2 Base Score = 9.3
Source: nvd.nist.gov | Generated: 2009-02-25 | Disagree?

Access_vector_2 Access_complexity_1 Authentication_2 Confidentiality_impact_2 Integrity_impact_2 Availability_impact_2

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2009/04/21 17:35:36 | Re: Problem installing updates for Office Pro 2007 and Vista

from: Microsoft Patch Watch

MS offers *no*-charge support for getting Security updates installed: MS09-009: Description of the security update for Excel 2007: April 14, 2009 link MowGreen =============== *-343-* FDNY Never

2009/03/12 16:52:57 | Protecting Yourself From Attempts to Exploit CVE-2009-0238

from: SecureWorks Research Blog

On February 24, 2009, Microsoft published Microsoft Security Advisory 968272 confirming the existence of a recently disclosed 0-day vulnerability in Microsoft Office Excel. For now, there are reports of only limited and targeted attacks attempting to exploit this vulnerability.

2009/03/05 22:55:00 | Excel zero-day patch not included in next Reboot Tuesday

from: Security4all - Dedicated to digital security, enterprise 2.0 and presentation skills

On the 24th of February, Microsoft released a security advisory for Excel (CVE-2009-0238): http://www.microsoft.com/technet/security/advisory/968272.mspx Quoting my previous post : Both McAfee

2009/03/02 17:19:57 | Feeling Vulnerable?

from: ThreatBlog

This is a follow up to David Harley’s post “Targeted Excel Malware Revisited ... , “X97M/Exploit.CVE-2009-0238.Gen.” id for the actual attempt to exploit the program. In other words

2009/03/02 11:29:41 | Targeted Excel Malware Revisited.

from: ThreatBlog

Further to our blog last week on targeted attacks exploiting a vulnerability found in a number of Excel versions including  Mac versions, viewers, ... , flagged as  X97M/Exploit.CVE-2009-0238.Gen. This detection was released on Friday evening

2009/02/24 22:33:00 | Trojans using an Excel 0-day roaming about

from: Security4all - Dedicated to digital security, enterprise 2.0 and presentation skills

This one is hot of the presses: Microsoft has released a security advisory for this issue (CVE-2009-0238): http://www.microsoft.com/technet/security/advisory/968272.mspx Many versions of Excel

2009/02/24 18:06:22 | New Excel Trojan Hits the Net

from: McAfee Avert Labs

– Update Feb 24, 10:15 PDT – Microsoft has released a security advisory for this issue (CVE-2009-0238): http://www.microsoft.com/technet/security/advisory/968272.mspx Many versions of Excel

2009/04/09 19:18:50 | Microsoft released April Patch list for Patch Tuesday

from: Tech-Linkblog.com

To see what systems are affected please see the bulletin for further details ... Code execution that needs to be fixed.  It looks like CVE-2009-0238 is the one that this is being

2009/04/14 17:49:59 | Microsoft Security Bulletin Summary for April 2009

from: Rod Trent at myITforum.com

-----Original Message----- From: Microsoft [mailto:Microsoft@newsletters.microsoft.com] Sent: Tuesday, April 14, 2009 1:27 PM To: rodtrent@myITforum.com Subject: Microsoft Security Bulletin Summary for April 2009 -----BEGIN PGP SIGNED MESSAGE----- Hash:

2009/04/14 17:34:34 | 8 Microsoft Patches Fix 21 Vulnerabilities

from: Security Watch

8 Microsoft updates today fix 23 reported vulnerabilities , many of them serious ... advisories from Microsoft: MS09-009: Vulnerabilities in Microsoft Office Excel Could Cause Remote Code

2009/04/14 17:08:00 | Microsoft Security Bulletin(s) for April 14, 2009

from: DP's Security Bits

Note: There may be latency issues due to replication, ... Explorer (963027) » www.microsoft.com/technet/securi···014.mspx Microsoft Security Bulletin MS09-009

2009/04/14 17:02:07 | Released: Eight New Microsoft Security Bulletins for April 2009

from: MSMVPS.COM

Microsoft has published eight new security bulletins today that affect Windows, Internet Explorer, Excel and ISA Server. Critical MS09-009 -  Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (968557) Critical MS09-010 -  Vulnerabilities in WordPad and Office Text

2009/04/15 00:00:00 | Microsoft Releases Patches For 23 Vulnerabilities

from: Hack In The Box

Microsoft will be launching a bunch of updates for its Office application suite and Internet Explorer in a few hours' time; ... that was discovered back in February 2009. Patches numbered MS09-009, MS09-010 and MS09-012 will hopefully close

2009/04/14 18:00:55 | Microsoft posts April 2009 security updates

from: SuperSite Blog

Nice and regular-like... As part of Microsoft’s commitment to deliver security updates on a predictable and consistent monthly schedule, ... . Microsoft’s April Bulletin Release MS09-009 (Maximum severity of Critical

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use