CVE-2006-1302: Buffer Overflow
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability described by CVE-2006-1302?
CVE-2006-1302 is a buffer overflow vulnerability in Microsoft Excel 2000 through 2003 that allows attackers to execute arbitrary code by using a crafted .xls file.
Which versions of Microsoft Excel are affected by CVE-2006-1302?
CVE-2006-1302 affects Microsoft Excel versions 2000, 2000 SP2, 2000 SP3, 2000 SR1, 2002, 2002 SP1, 2002 SP2, 2002 SP3, 2003, and Excel Viewer 2003.
What is the impact of CVE-2006-1302 if exploited?
If exploited, CVE-2006-1302 can cause memory corruption that leads to arbitrary code execution.
How can I mitigate the risks associated with CVE-2006-1302?
To mitigate the risks of CVE-2006-1302, users should avoid opening .xls files from untrusted sources and apply available patches from Microsoft.
Is there a patch available for fixing CVE-2006-1302?
Yes, Microsoft has released security updates that address the vulnerabilities found in Excel versions affected by CVE-2006-1302.