Affected Versions:
Microsoft Excel 2007 SP2
Microsoft Excel 2007 SP1
Microsoft Office 2004 for Mac vulnerability description:
Excel is a workbook tool in Microsoft office suites.
An uninitialized memory vulnerability exists in Excel parsing the FnGroupName, BuiltInFnGroupCount, and fnkg12 malformed records in the XSL file. attackers who successfully exploit this vulnerability can completely control the affected system. <* Reference
Http://secunia.com/advisories/38805/
Http://www.us-cert.gov/cas/techalerts/TA10-068A.html
*>
SEBUG Security suggestions:
Temporary solution:
* Use Microsoft Office file blocking policies to prevent opening documents of Office 2003 and earlier versions from unknown or untrusted sources.
* When you open a file from an unknown or untrusted source, use Microsoft Office to isolate the Conversion Environment (MOICE ).
* Do not open Excel files accidentally received from untrusted sources.
Vendor patch:
Microsoft
---------
Microsoft has released a Security Bulletin (MS10-017) and patches for this:
MS10-017: Vulnerabilities in Microsoft Office Excel cocould Allow Remote Code Execution (980150)