VYPR
Unrated severityNVD Advisory· Published Apr 13, 2011· Updated Apr 29, 2026

CVE-2011-0097

CVE-2011-0097

Description

Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via a crafted 400h substream in an Excel file, which triggers a stack-based buffer overflow, aka "Excel Integer Overrun Vulnerability."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Integer underflow in Microsoft Excel allows remote code execution via a crafted 400h substream, affecting multiple versions.

Vulnerability

Integer underflow vulnerability in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2. The flaw exists when parsing a specially crafted 400h substream in an Excel file, leading to a stack-based buffer overflow [1][2].

Exploitation

An attacker must craft a malicious Excel file and convince the target to open it, typically via email or web download. No additional authentication is required; the vulnerability is triggered upon opening the file, resulting in memory corruption [1][3].

Impact

Successful exploitation grants the attacker arbitrary code execution in the context of the logged-on user. If the user has administrative rights, the attacker can take complete control of the system [1].

Mitigation

Microsoft released security update MS11-021 on April 12, 2011, which addresses this vulnerability for all affected software. Users should apply the update via Windows Update or direct download [1]. No workarounds are documented for unpatched systems.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

13

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.