CVE-2009-3129
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."
- Affected products
- Office Excel, Office Compatibility Pack, Office Excel Viewer, Open Xml File Format Converter For Mac
- Microsoft Excel
- = 2002, 2003, 2007
- Microsoft Excel Viewer
- All versions
- Microsoft Office
- = 2004, 2008
- Microsoft Open Xml File Format Converter
- All versions
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 85.7% (100th percentile)
- Weakness
- CWE-787
- NVD status
- Analyzed
- Published
- 2009-11-11
CVE-2009-3129 at NVD
10 known exploits for CVE-2009-3129
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft-Excel-Malformed-FEATHEADER
MS Excel Malformed FEATHEADER Record Exploit (MS09-067)
Microsoft Excel - Malformed FEATHEADER Record (MS09-067) (Metasploit)
MS Excel Malformed FEATHEADER Record Exploit
Microsoft Excel Featheader Buffer Overflow
Microsoft Excel - FEATHEADER Record (MS09-067)
Microsoft Excel - FEATHEADER Record (MS09-067)
Microsoft Excel Malformed FEATHEADER Record Vulnerability
Microsoft Excel FEATHEADER记录内存破坏漏洞(MS09-067)
Microsoft-Excel-Record