BDU:2022-04047

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

9.6critical3.x
0246810

CVSS Score: 9.6/10

All CVSS Scores

CVSS 3.x
9.6

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

Уязвимость пакета программ Microsoft Office связана со смещением указателей при обработке элемента размера cbHdrData записи FEATHEADER файлов формата BIFF. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код или получить полный контроль над приложением

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

bdu

Related Vulnerabilities

Exploits

Exploit ID: BDU:2022-04047

Source: bdu_exploit

URL: https://bdu.fstec.ru/vul

Exploit ID: 14706

Source: exploitdb

URL: https://www.exploit-db.com/exploits/14706

Exploit ID: 16625

Source: exploitdb

URL: https://www.exploit-db.com/exploits/16625

Recommendations

Source: bdu

Использование рекомендаций:
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-067

URL: https://bdu.fstec.ru/vul/2022-04047

Vulnerable Software (10)

Type: Configuration

Vendor: microsoft corp

Product: microsoft excel viewer 2003 service pack 3

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft excel viewer service pack 1

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft excel viewer service pack 2

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office 2003 service pack 3

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office 2004

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office 2007 service pack 1

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office 2007 service pack 2

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: microsoft office 2008

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

Type: Configuration

Vendor: microsoft corp

Product: open xml file format converter

Operating System: * *

Trait:
{  "version_exact": "*"}

Source: bdu

End of list