CVE-2011-0978 is a stack-based buffer overflow vulnerability affecting multiple versions of Microsoft Excel, Excel Viewer, and Office Compatibility Pack. This flaw, stemming from improper array indexing related to an axis properties record, allows unauthenticated remote attackers to execute arbitrary code. With a CVSS score of 9.3, it is a critical vulnerability requiring medium attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, a Proof-of-Concept exploit is publicly available on ExploitDB, and it has garnered some community discussion and media coverage, including a mention in a SecurityWeek article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2002CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2003:sp3:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2007:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:excel_viewer:-:sp2:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.