Intrusion Prevention

MS.Excel.AutoFilter.Record.Memory.Corruption

Description

This indicates an attack attempt to exploit a memory-corruption vulnerability in Microsoft Excel.
The vulnerability is caused by the application's failure to correctly parse BIFF8 format Excel files. It may allow remote attackers to execute arbitrary code by sending a BIFF8 format Excel file with a crafted AutoFilter filter record.

Affected Products

Microsoft Excel Viewer 2003
Microsoft Excel 2004 for Mac
Microsoft Excel 2003 SP3
Microsoft Excel 2003 SP2
Microsoft Excel 2003 SP1
Microsoft Excel 2003
Microsoft Excel 2002 SP3
Microsoft Excel 2002 SP2
Microsoft Excel 2002 SP1
Microsoft Excel 2002
Microsoft Excel 2000 SR1
Microsoft Excel 2000 SP3
Microsoft Excel 2000 SP2
Microsoft Excel 2000
Avaya CIE 1.0

Impact

Privilege escalation.

Recommended Actions

Microsoft has released a fix to address this issue:
http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx

CVE References

CVE-2007-1214