CVE-2010-1245 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 22.4% (pctl 98)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 22.36% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-06-08 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | excel |
| microsoft | office |
| microsoft | open xml file format converter |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Excel - SxView Record Parsing Heap Memory Corruption | 2010-09-29 |
References
- http://www.securityfocus.com/archive/1/511753/100/0/threaded
- http://www.us-cert.gov/cas/techalerts/TA10-159B.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6877
- http://www.securityfocus.com/archive/1/511753/100/0/threaded
- http://www.us-cert.gov/cas/techalerts/TA10-159B.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6877
→ the Explorer · watch your stack · NVD