Immunity, Inc.
Name wp_ms11_021
CVE CVE-2011-0105
Exploit Pack White_Phosphorus
DescriptionMS11-021: Office 2007 Excel Record Parsing WriteAV Clientside Overflow
NotesReferences: http://technet.microsoft.com/en-us/security/bulletin/MS11-021
http://www.abysssec.com/blog/2011/11/02/microsoft-excel-2007-sp2-buffer-overwrite-vulnerability-ba-exploit-ms11-021/
CVE Name: CVE-2011-0105
VENDOR: Microsoft
Notes:
This is a client-side exploit - run the module and send the created file to the target user.
Vista and 7 are unexploitable as Excel attempts to recover the file.

Repeatability: Unlimited
Date public: 2011-04-12
CVE Url: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0105
CVSS: 9.3

Learn more about the CANVAS Exploit Pack here: White_Phosphorus