Code Execution Vulnerability in Microsoft Office Products
CVE-2010-0263
Currently unrated
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 10 March 2010
Summary
A vulnerability exists in various Microsoft Office products due to improper validation of ZIP headers during the decompression of Open XML (.XLSX) documents. This flaw can be exploited by remote attackers to execute arbitrary code on affected systems. It specifically targets uninitialized memory locations through crafted XLSX files, potentially leading to unauthorized access and control over the system.
References
EPSS Score
60% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved