Sploitus

Exploit for Microsoft Office Excel Malformed Obj Record Stack Buffer Overflow

saint Β· 2010-07-22

Exploit Code

MARKDOWN37 lines
## https://sploitus.com/exploit?id=SAINT:755FB97470B9E56D18723D2C946D9F8B
Added: 07/22/2010  
CVE: [CVE-2010-0822](<https://vulners.com/cve/CVE-2010-0822>)  
BID: [40520](<http://www.securityfocus.com/bid/40520>)  
OSVDB: [65236](<http://www.osvdb.org/65236>)  


### Background

Microsoft Excel, part of the [Microsoft Office](<http://office.microsoft.com>) product suite, is a spreadsheet application for Windows and Macintosh platforms. 

### Problem

Microsoft Excel is vulnerable to a buffer overflow when processing malformed OBJ (recType 0x5D) records. This vulnerability could be exploited to execute arbitrary code by tricking a user into opening a specially crafted Excel document. 

### Resolution

Apply the patch referenced in [Microsoft Security Bulletin 10-038](<http://www.microsoft.com/technet/security/bulletin/MS10-038.mspx>). 

### References

<http://secunia.com/advisories/37500/>  


### Limitations

Exploit works on Microsoft Office Excel 2007 SP2 and requires a user to open the exploit file in Microsoft Office Excel. 

Macros must be enabled in Excel. 

There may be a delay before the exploit succeeds. 

This exploit requires the Compress::Zlib PERL module. 

### Platforms

Windows