Code Execution Vulnerability in Microsoft Office Products
CVE-2010-0263

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
10 March 2010

Summary

A vulnerability exists in various Microsoft Office products due to improper validation of ZIP headers during the decompression of Open XML (.XLSX) documents. This flaw can be exploited by remote attackers to execute arbitrary code on affected systems. It specifically targets uninitialized memory locations through crafted XLSX files, potentially leading to unauthorized access and control over the system.

References

EPSS Score

60% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.