CVE-2008-0113
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 42%
from disclosure to weapon19 days
Published on NVDMar 11
1st PoC+19d
exploitation probability
42%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/5320⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=120585858807305&w=2https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-016http://secunia.com/advisories/29321https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5421http://www.securityfocus.com/archive/1/489415/100/0/threadedhttp://www.securitytracker.com/id?1019578http://www.us-cert.gov/cas/techalerts/TA08-071A.htmlhttp://www.vupen.com/english/advisories/2008/0848/referenceshttp://www.zerodayinitiative.com/advisories/ZDI-08-008