Intrusion Prevention

MS.Excel.SHRFMLA.Remote.Code.Execution

Description

This indicates an attack attempt to exploit a remote Code Execution vulnerability in Microsoft Excel.
The vulnerability is caused by an error that occurs when the vulnerable software handles a malicious "XLS" file. A remote attacker can exploit this to execute arbitrary code via a crafted "XLS" file.

Affected Products

Microsoft Excel 2003
Microsoft Excel 2007
Microsoft Excel 2010
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Microsoft Office for Mac 2011
all supported versions of Microsoft Excel Viewer
Microsoft Excel Services installed on SharePoint Server 2007
Microsoft Excel Services installed on SharePoint Server 2010
and Microsoft Excel Web App 2010.

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrades or patches from the vendor:
http://www.microsoft.com/technet/security/Bulletin/MS11-072.mspx

CVE References

CVE-2011-1986