iDefense Security Advisory 08.11.09 – Remote exploitation of a stack based buffer overflow vulnerability in Microsoft Corp.’s Office Web Components 2000 could allow an attacker to execute arbitrary code with the privileges of the logged on user. When instantiating a Spreadsheet object, it is possible to pass the object a parameter that refers to an Excel file that will be retrieved and then loaded. By using a long string for the parameter, it is possible to case a stack based buffer overflow. iDefense has confirmed the existence of this vulnerability in Microsoft Office XP Service Pack 3.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/80513/08.11.09-1.txt
Source: https://packetstormsecurity.com/files/80513/iDEFENSE-Security-Advisory-2009-08-11.1.html