Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Microsoft Excel Obj BIFF Record Boundary Access (MS11-045; CVE-2011-1272)

Subscribe

Check Point Reference: CPAI-2011-287
Date Published:
Severity:
Last Updated:
Source: Microsoft Security Bulletin MS11-045
Industry Reference(s): CVE-2011-1272
Protection Provided by: Security Gateway
  • R75
  • R71
  • R70
VPN-1
  • NGX R65
IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Microsoft Excel 2002 Service Pack 3
Microsoft Excel 2003 Service Pack 3
Microsoft Excel 2007 Service Pack 2
Microsoft Excel 2010 (32-bit editions)
Microsoft Excel (64-bit editions)
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Microsoft Office for Mac 2011
Open XML File Format Converter for Mac
Microsoft Excel Viewer Service Pack 2
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2
Vulnerability Description
A remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Update/Patch Available
Apply patches from Microsoft Security Bulletin MS11-045
Vulnerability Details
The vulnerability is caused when Microsoft Excel insufficiently validates Excel record structures while parsing specially crafted Excel files.

Protection Overview
This protection detect and block transfer of malformed Excel files over HTTP.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway R70 / R71 / R75

How Can I Protect My Network?

  1. In the IPS tab, click Protections and find the Microsoft Excel Insufficient Record Validation Vulnerability (MS11-045) protection using the Search tool and Edit the protection's settings.
  2. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Content Protection Violation
Attack Information: Excel Insufficient Record Validation Vulnerability (MS11-045)

IPS-1 & IPS1-NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Network Security > SMB, and select the SMB2 Create protection group.
3. Click Microsoft SMB Create Response Remote Code Execution (MS11-043) (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?

Upon attack, the following entries will be logged:

Alert Name: SMB2 Create
Description: Microsoft SMB Create Response Remote Code Execution (MS11-043)