Update Protection against Microsoft Excel Remote Code Execution Vulnerability (MS07-036)
| Check Point Reference: | CPAI-2007-085 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Bulletin MS07-036 | |
| Industry Reference(s): | ||
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Microsoft Excel 2000 SP3 Microsoft Excel 2002 SP3 Microsoft Excel 2003 SP2 Microsoft Excel 2003 Viewer Microsoft Office Excel 2007 Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats | ||
| Vulnerability Description Multiple vulnerabilities have been identified in Microsoft Excel. Microsoft Excel is a popular spreadsheet application. A remote attacker could exploit these issues via a malformed Excel file. Successful exploitation of these vulnerabilities may allow execution of arbitrary code on a target system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS07-036 |
|
|
Vulnerability Details The vulnerabilities are due to memory corruption errors in Microsoft Excel that fails to properly handle malformed Excel files. An attacker can exploit this flaw to take complete control over a vulnerable system via a specially crafted Excel file. |
Protection Overview
By enabling this protection, SmartDefense will detect and block the transferring of malformed Excel files over HTTP.
In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The Update released on August 6, 2007 includes the following protections:
Microsoft Excel Remote Code Execution Vulnerability (MS07-036) CPAI-2007-085
Multiple Microsoft Windows Active Directory Crafted LDAP Request Vulnerabilities (MS07-039) CPAI-2007-086
Microsoft Office Publisher 2007 Remote Code Execution Vulnerability (MS07-037) CPAI-2007-087