CVE-2006-1306: Code Injection
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1306?
CVE-2006-1306 has a critical severity level due to its ability to allow arbitrary code execution.
How do I fix CVE-2006-1306?
To remediate CVE-2006-1306, users should update Microsoft Excel to the latest version available that addresses this vulnerability.
Which versions of Excel are affected by CVE-2006-1306?
CVE-2006-1306 affects Microsoft Excel versions 2000, 2002, 2003, and 2004 for Mac, along with Excel Viewer 2003.
Can CVE-2006-1306 be exploited without user interaction?
Exploitation of CVE-2006-1306 requires user interaction, as it necessitates opening a specially crafted .xls file.
What type of attacks are associated with CVE-2006-1306?
CVE-2006-1306 is associated with attacks that leverage malformed BIFF records in Excel files to execute arbitrary code.