U bevindt zich in: Panda Security > Home Users > security-info > overview
Active Scan. Scan gratis uw PC
Download Cloud Antivirus Gratis

Virusencyclopedie

Welkom bij de virusencyclopedie van Panda Security.

MS10-057

Threat LevelLow threatDamageHighDistributionNot widespread
Common name:MS10-057
Technical name:MS10-057
Threat level:Medium
Alias:Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution
Type:Vulnerability
Effects:  

It is an important vulnerability in certain versions of Excel, which allows hackers to gain remote control of the affected computer with the same privileges as the logged-on user.

Affected platforms:

Other

First detected on:Aug. 11, 2010
Detection updated on:Aug. 25, 2010
StatisticsNo

Brief Description 

    

MS10-057 is not categorized as virus, worm, Trojan or backdoor. It is an important vulnerability in certain versions of Excel, which allows arbitrary code to be remotely executed in the vulnerable computer.

The affected versions are:

  • Excel 2003/2002.
  • Office 2008/2004 for Mac.
  • Open XML File Format Converter for Mac.

If exploited successfully, it allows hackers to gain remote control of the affected computer with the same privileges as the logged-on user. If this user had administrator rights, the hacker could take complete control of the system: create, modify or delete files, install programs, create new user accounts, etc.

MS10-057 is usually exploited by creating a specially crafted Excel file and sending it via email or hosting it in a website and convincing users to open it.

 

If you have any of the vulnerable Office components installed on your computer, it is recommended to download and apply the security patch for this vulnerability. Click here to access the web page for downloading the patch.

Bear in mind that MS10-057 replaces a previous bulletin, called MS10-038.