Vulnerability record · CVE-2008-3471 · published 15 October 2008
CVE-2008-3471: Microsoft Excel BIFF file parsing stack buffer overflow
Microsoft · Excel
Microsoft Excel and related Excel viewers and converters contain a stack-based buffer overflow when parsing a BIFF file with a malformed record that triggers a user-influenced size calculation. Opening a crafted spreadsheet can corrupt the stack and allow arbitrary code execution in the context of the user. The flaw affects Excel 2000 through 2007, Excel Viewer 2003, the Office Compatibility Pack, Office for Mac 2004/2008, and the Open XML File Format Converter for Mac.
Description
Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a BIFF file with a malformed record that triggers a user-influenced size calculation, aka "File Format Parsing Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with complete impact and a very high EPSS score, tempered by the requirement that a user open a crafted file and by the age of the affected products.
What it is
Microsoft Excel and related Excel viewers and converters contain a stack-based buffer overflow when parsing a BIFF file with a malformed record that triggers a user-influenced size calculation. Opening a crafted spreadsheet can corrupt the stack and allow arbitrary code execution in the context of the user. The flaw affects Excel 2000 through 2007, Excel Viewer 2003, the Office Compatibility Pack, Office for Mac 2004/2008, and the Open XML File Format Converter for Mac.
Impact
An attacker who gets a victim to open a malicious BIFF file can execute arbitrary code with the privileges of the logged-on user, giving full control of confidentiality, integrity and availability on that host.
Attack surface
Reached remotely by delivering a crafted BIFF spreadsheet file, typically via email attachment or a hosted download; no authentication is required, but the victim must open the file, which is why the CVSS vector is AV:N/AC:M/Au:N.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at roughly 0.52 (99th percentile), and references include a Zero Day Initiative advisory, indicating public technical detail exists.
What to do
- Apply Microsoft security bulletin MS08-057 for all affected Excel, Excel Viewer, Compatibility Pack, Office for Mac and Open XML File Format Converter installations
- Upgrade off end-of-life Excel 2000/2002/2003 and Office 2004 for Mac to a supported release
- Block or strip untrusted spreadsheet attachments at the mail and web gateway, and enforce Mark-of-the-Web/Protected View so files open in a restricted mode
- Disable or restrict Excel Viewer and the Open XML File Format Converter where they are not operationally required
- Run users with least privilege so code execution does not inherit administrative rights
Detection
- Hunt for Excel, Excel Viewer or Open XML File Format Converter processes spawning child processes such as cmd.exe, powershell.exe or wscript.exe
- Monitor for spreadsheet files written to temp or startup locations shortly after an Office application opens an email or download
- Alert on Office application crashes or stack-corruption events correlated with recently opened BIFF/XLS files
- Review proxy and mail logs for inbound spreadsheet attachments from untrusted senders or newly registered domains
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-3471 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-3471), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.