CVE-2010-0822 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 70.1% (pctl 99)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 70.12% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-06-08 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | excel |
| microsoft | office |
| microsoft | open xml file format converter |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Excel - Malformed OBJ Record Handling Overflow (MS11-038) (Metasploit) | 2011-11-22 |
| exploit-db | Microsoft Excel - OBJ Record Stack Overflow | 2010-09-24 |
| exploit-db | Microsoft Excel - 0x5D record Stack Overflow (MS10-038) | 2010-07-14 |
References
- http://osvdb.org/65236
- http://www.securityfocus.com/archive/1/511752/100/0/threaded
- http://www.securityfocus.com/bid/40520
- http://www.us-cert.gov/cas/techalerts/TA10-159B.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7265
- http://osvdb.org/65236
- http://www.securityfocus.com/archive/1/511752/100/0/threaded
- http://www.securityfocus.com/bid/40520
- http://www.us-cert.gov/cas/techalerts/TA10-159B.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7265
→ the Explorer · watch your stack · NVD