hathat Posted November 4, 2012 Report Posted November 4, 2012 Microsoft Office Excel 2010 Crash PoCTitle : Microsoft Office Excel 2010 memory corruptionVersion : Microsoft Office professional Plus 2010Date : 2012-10-27Vendor : http://office.microsoft.comImpact : Med/HighContact : coolkaveh [at] rocketmail.comTwitter : @coolkavehtested : XP SP3 ENG###############################################################################Bug :----memory corruption during the handling of the xls files a context-dependent attackercan execute arbitrary code.----################################################################################(b4c.1350): Access violation - code c0000005 (first chance)First chance exceptions are reported before any exception handling.This exception may be expected and handled.eax=00000584ebx=00135070ecx=00001000edx=0000105fesi=06a80800edi=00000040eip=301ce0d0esp=001302f0ebp=00131d6c iopl=0 nv up ei pl zr na pe nccs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00010246*** ERROR: Symbol file could not be found. Defaulted to export symbols for Excel.exe -Excel!Ordinal40+0x1ce0d0:301ce0d0 668b5008 mov dx,word ptr [eax+8] ds:0023:0000058c=????################################################################################Proof of concept included.Zippyshare.com - POC.rarhttp://www.exploit-db.com/sploits/22330.rarSursa Microsoft Office Excel 2010 Crash PoC Quote