First published: Thu Jul 13 2006(Updated: )
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2000 | |
Microsoft Office Excel | =2000-sp2 | |
Microsoft Office Excel | =2000-sp3 | |
Microsoft Office Excel | =2000-sr1 | |
Microsoft Office Excel | =2002 | |
Microsoft Office Excel | =2002-sp1 | |
Microsoft Office Excel | =2002-sp2 | |
Microsoft Office Excel | =2002-sp3 | |
Microsoft Office Excel | =2003 | |
Microsoft Office Excel | =2003-sp1 | |
Microsoft Office Excel | =2004 | |
Microsoft Office Excel | =x | |
Microsoft Office Excel Viewer | =2003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1302 is a buffer overflow vulnerability in Microsoft Excel 2000 through 2003 that allows attackers to execute arbitrary code by using a crafted .xls file.
CVE-2006-1302 affects Microsoft Excel versions 2000, 2000 SP2, 2000 SP3, 2000 SR1, 2002, 2002 SP1, 2002 SP2, 2002 SP3, 2003, and Excel Viewer 2003.
If exploited, CVE-2006-1302 can cause memory corruption that leads to arbitrary code execution.
To mitigate the risks of CVE-2006-1302, users should avoid opening .xls files from untrusted sources and apply available patches from Microsoft.
Yes, Microsoft has released security updates that address the vulnerabilities found in Excel versions affected by CVE-2006-1302.