← Back

CVE-2008-3003

nvd nist
Published: Aug 12, 2008Modified: Apr 23, 2026

JSON object

Loading...
6.6
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:N
Exploitability: 3.9 / Impact: 9.2
Source: NVD

Description

Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."

Affected (3)

Products: Microsoft: Office
1 product
Office
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2007
Version 2007
Version 2007 sp1

References (16)

Source: secure@microsoft.com
Vendor Advisory
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
US Government Resource
Source: secure@microsoft.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.