=====================================================================
                                   CERT-Renater

                        Note d'Information No. 2010/VULN411
_____________________________________________________________________

DATE                      : 14/10/2010

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running Microsoft Office, Open XML File Format Converter for Mac,
                             Microsoft Excel Viewer, Microsoft Office Compatibility Pack for Word, Excel, and
                              PowerPoint 2007 File Formats.

======================================================================
KB2293211
http://www.microsoft.com/technet/security/bulletin/MS10-080.mspx
______________________________________________________________________

Microsoft Security Bulletin MS10-080 - Important
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2293211)

Version: 1.0

General Information

Executive Summary

This security update resolves thirteen privately reported vulnerabilities in
Microsoft Office. The vulnerabilities could allow remote code execution if a
user opens a specially crafted Excel file or a specially crafted Lotus 1-2-3
file. An attacker who successfully exploited any of these vulnerabilities
could gain the same user rights as the local user. Users whose accounts are
configured to have fewer user rights on the system could be less impacted than
users who operate with administrative user rights.

This security update is rated Important for all supported editions of
Microsoft Excel 2002, Microsoft Excel 2003, Microsoft Excel 2007, Microsoft
Office 2004 for Mac, and Microsoft Office 2008 for Mac; Open XML File Format
Converter for Mac; and all supported versions of Microsoft Office Excel Viewer
and Microsoft Office Compatibility Pack. For more information, see the
subsection, Affected and Non-Affected Software, in this section.

Affected Software

Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 3
Microsoft Office 2007 Service Pack 2
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Open XML File Format Converter for Mac
Microsoft Excel Viewer Service Pack 2
Microsoft Office Compatibility Pack for Word, Excel, and
  PowerPoint 2007 File Formats Service Pack 2

Vulnerability Information

Excel Record Parsing Integer Overflow Vulnerability - CVE-2010-3230

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel Record Parsing Memory Corruption Vulnerability - CVE-2010-3231

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Excel File Format Parsing Vulnerability - CVE-2010-3232

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Lotus 1-2-3 Workbook Parsing Vulnerability - CVE-2010-3233

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Lotus 1-2-3 workbook files (.wk3). An attacker who
successfully exploited this vulnerability could take complete control of an
affected system. An attacker could then install programs; view, change, or
delete data; or create new accounts with full user rights.

Formula Substream Memory Corruption Vulnerability - CVE-2010-3234

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Formula Biff Record Vulnerability - CVE-2010-3235

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Out Of Bounds Array Vulnerability - CVE-2010-3236

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Merge Cell Record Pointer Vulnerability - CVE-2010-3237

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Negative Future Function Vulnerability - CVE-2010-3238

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Extra Out of Boundary Record Parsing Vulnerability - CVE-2010-3239

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Out-of-Bounds Memory Write in Parsing Vulnerability - CVE-2010-3241

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

Ghost Record Type Parsing Vulnerability - CVE-2010-3242

A remote code execution vulnerability exists in the way that Microsoft Excel
handles specially crafted Excel files. An attacker who successfully exploited
this vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or create
new accounts with full user rights.

======================================================================

          =========================================================
          Les serveurs de référence du CERT-Renater
          http://www.urec.fr/securite
          http://www.cru.fr/securite
          http://www.renater.fr
          =========================================================
          + CERT-RENATER          | tel : 01-53-94-20-44          +
          + 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
          + 75013 Paris           | email: certsvp@renater.fr     +
          =========================================================



