## https://sploitus.com/exploit?id=SAINT:0D99A3060A6C5D31B8F225079FA005B2
Added: 08/15/2011
CVE: [CVE-2011-1276](<https://vulners.com/cve/CVE-2011-1276>)
BID: [48161](<http://www.securityfocus.com/bid/48161>)
OSVDB: [72924](<http://www.osvdb.org/72924>)
### Background
Microsoft Excel, part of the [Microsoft Office](<http://office.microsoft.com>) product suite, is a spreadsheet application for Windows and Macintosh platforms.
### Problem
Microsoft Office Excel is vulnerable to remote code execution due to improper boundary checking while parsing SLK data exchange files that results in buffer overflow. A remote attacker can exploit this vulnerability by enticing a target user to open a malicious Excel file, potentially causing arbitrary code to be injected and executed in the security context of the currently logged on user.
### Resolution
Apply the patch referenced in [Microsoft Security Bulletin 11-045](<http://www.microsoft.com/technet/security/bulletin/MS11-045.mspx>).
### References
<http://secunia.com/advisories/44901/>
### Limitations
Exploit works on Microsoft Excel 2002 SP3 on Windows XP SP3 English (DEP OptIn) with KB2483185.
The target user must open the exploit file in Microsoft Excel 2002 SP3.
### Platforms
Windows