CVE-2006-1304: Code Injection
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1304?
CVE-2006-1304 has a severity rating that allows for potential remote code execution, making it critical for affected users.
How do I fix CVE-2006-1304?
To fix CVE-2006-1304, users should apply the latest security patches provided by Microsoft for the affected versions of Excel.
Which versions of Microsoft Excel are affected by CVE-2006-1304?
CVE-2006-1304 affects Microsoft Excel 2000, 2002, and 2003, including various service packs and the Excel Viewer.
What is the nature of the vulnerability in CVE-2006-1304?
CVE-2006-1304 is a buffer overflow vulnerability that can be triggered by a specially crafted .xls file.
Can CVE-2006-1304 be exploited without user action?
CVE-2006-1304 requires user-assisted actions, such as opening a malicious .xls file, to exploit the vulnerability.