Vulnerability Details CVE-2008-3006
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 Gold and SP3; Office Excel Viewer; Office Compatibility Pack 2007 Gold and SP1; Office SharePoint Server 2007 Gold and SP1; and Office 2004 and 2008 for Mac do not properly parse Country record values when loading Excel files, which allows remote attackers to execute arbitrary code via a crafted Excel file, aka the "Excel Record Parsing Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.683
EPSS Ranking 98.5%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2008-3006
-
cpe:2.3:a:microsoft:office:2000
-
cpe:2.3:a:microsoft:office:2003
-
cpe:2.3:a:microsoft:office:2004
-
cpe:2.3:a:microsoft:office:2007
-
cpe:2.3:a:microsoft:office:2008
-
cpe:2.3:a:microsoft:office:xp
-
cpe:2.3:a:microsoft:office_compatibility_pack:2007
-
cpe:2.3:a:microsoft:office_excel_viewer:2003
-
cpe:2.3:a:microsoft:sharepoint_server:2007