[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : MOAUB #29 - Microsoft Excel SxView Record Parsing Heap Memory Corruption
# Published : 2010-09-29
# Author : Abysssec
# Previous Title : MOAUB #30 - Microsoft Unicode Scripts Processor Remote Code Execution
# Next Title : Fox Audio Player 0.8.0 .m3u Denial of Service Vulnerability
'''
__ __ ____ _ _ ____
| / |/ __ / | | | | _
| / | | | | / | | | | |_) |
| |/| | | | |/ / | | | | _ < (day 29 binary analysis)
| | | | |__| / ____ |__| | |_) |
|_| |_|____/_/ _____/|____/
'''
Title : Microsoft Excel SxView Record Parsing Heap Memory Corruption
Version : Excel 2002 SP3
Analysis : http://www.abysssec.com
Vendor : http://www.microsoft.com
Impact : High
Contact : shahin [at] abysssec.com , info [at] abysssec.com
Twitter : @abysssec
CVE : CVE-2010-1245
here is BA : http://www.exploit-db.com/moaub-29-microsoft-excel-sxview-record-parsing-memory-corruption/
here is the PoC : http://www.exploit-db.com/sploits/moaub-29-exploit.rar
t