CVE-2006-0028: Medium severity Microsoft Excel vulnerability
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0028?
CVE-2006-0028 has been classified as a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2006-0028?
To fix CVE-2006-0028, users are advised to apply the latest security updates provided by Microsoft for affected versions of Excel and Office.
Which versions of Microsoft products are affected by CVE-2006-0028?
CVE-2006-0028 affects multiple versions of Microsoft Excel and Office, including 2000, 2002, 2003, and their respective service packs.
What type of attacks can exploit CVE-2006-0028?
CVE-2006-0028 can be exploited by user-assisted attackers through specially crafted BIFF files containing malformed BOOLERR records.
Is there a workaround for CVE-2006-0028?
Currently, the best workaround for CVE-2006-0028 is to avoid opening unknown or suspicious BIFF format files until patches are applied.