漏洞描述 Microsoft Office Excel是Office套件中的电子表格工具。 Microsoft Office Excel在解析电子表格中的DBQueryExt记录时没有正确地检查其中的ADO字段,可能导致调用用户所控制的指针。用户受骗打开了恶意文件就可能触发这个漏洞,导致执行任意代码。
相关漏洞推荐 POC sharepoint-lists-api-disclosure: Microsoft SharePoint - List API Disclosure POC sharepoint-layouts-disclosure: Microsoft SharePoint - Layouts Disclosure POC sharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page Disclosure POC sharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata Disclosure POC sharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages Disclosure 新视窗新一代物业管理系统 /OfficeManagement/RegisterManager/Report/Training/Report/GetprintData.asmx SQL 注入漏洞 九思OA /jsoa/OfficeServer 文件上传漏洞 POC CVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass 万户ezOFFICE协同平台 /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../modules/hrm/report/customize/checkSQL_httprequest.jsp SQL 注入漏洞 用友NC /portal/pt/infopathimport/importExcelTemplate pageId 文件上传漏洞 红帆 IOffice MobileBind.aspx SQL注入漏洞 关于portal端importExcelTemplate接口任意文件上传漏洞修复通告 (CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行