Vulnerability record · CVE-2010-0258 · published 10 March 2010
CVE-2010-0258: Microsoft Excel Sheet Object Type Confusion Enables Code Execution
Microsoft · Excel
Microsoft Excel and related Office components fail to properly parse the Excel file format, causing memory to be interpreted as a different object type than intended. A crafted spreadsheet can trigger this type confusion and lead to arbitrary code execution in the context of the user. The flaw affects multiple Excel versions and viewers across Windows and Mac platforms.
Description
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that causes memory to be interpreted as a different object type than intended, aka "Microsoft Office Excel Sheet Object Type Confusion Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 and very high EPSS percentile indicate significant risk, though exploitation requires user interaction and no active KEV listing exists.
What it is
Microsoft Excel and related Office components fail to properly parse the Excel file format, causing memory to be interpreted as a different object type than intended. A crafted spreadsheet can trigger this type confusion and lead to arbitrary code execution in the context of the user. The flaw affects multiple Excel versions and viewers across Windows and Mac platforms.
Impact
An attacker who convinces a user to open a malicious spreadsheet can execute arbitrary code with the privileges of that user. This can result in full compromise of the user's system, including data theft, installation of malware, or further lateral movement.
Attack surface
The vulnerability is reached locally through a crafted Excel file opened by the victim, requiring user interaction (UI:R) and no prior authentication (PR:N). It can be delivered via email attachment, web download, or shared document.
Exploitation
The CVE is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS indicates a high probability of exploitation activity (0.6095, 99.1st percentile). References include a vendor patch and US-CERT advisory, but no public exploit tags are present.
What to do
- Apply the Microsoft security update MS10-017 immediately to all affected Excel and Office components.
- Disable or restrict opening of untrusted Excel files from email and web sources until patching is complete.
- Use Microsoft Office File Block policies to prevent older Excel formats from being opened by default.
- Educate users not to open unexpected spreadsheets, especially from external senders.
- Consider application whitelisting or sandboxing for Office processes to limit the impact of successful exploitation.
Detection
- Monitor for Excel processes spawning child processes such as cmd.exe, powershell.exe, or wscript.exe, which may indicate exploitation.
- Inspect email gateways and endpoint logs for Excel file attachments with unusual or malformed structures.
- Use endpoint detection to flag crashes or memory corruption events in Excel or related Office components.
- Review Windows event logs for application errors or unexpected process creation originating from Office applications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=859 | Broken Link |
| http://www.securitytracker.com/id?1023698 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.us-cert.gov/cas/techalerts/TA10-068A.html | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-017 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8545 | Broken Link |
| http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=859 | Broken Link |
| http://www.securitytracker.com/id?1023698 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.us-cert.gov/cas/techalerts/TA10-068A.html | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-017 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8545 | Broken Link |
Track CVE-2010-0258 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0258), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.