peter bassill · operator
$ cve CVE-2011-0104 JSON

CVE-2011-0104 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 53.4% (pctl 99)

Patch early

A public exploit exists.

Description

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS53.43% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2011-04-13
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftexcel
microsoftoffice
microsoftopen xml file format converter

Public exploits

SourceTitleDate
exploit-dbMicrosoft Excel - Remote Buffer Overflow2011-04-12

References

→ the Explorer  ·  watch your stack  ·  NVD