First published: Thu Jul 13 2006(Updated: )
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2000 | |
Microsoft Office Excel | =2000-sp2 | |
Microsoft Office Excel | =2000-sp3 | |
Microsoft Office Excel | =2000-sr1 | |
Microsoft Office Excel | =2002 | |
Microsoft Office Excel | =2002-sp1 | |
Microsoft Office Excel | =2002-sp2 | |
Microsoft Office Excel | =2002-sp3 | |
Microsoft Office Excel | =2003 | |
Microsoft Office Excel | =2003-sp1 | |
Microsoft Office Excel | =2004 | |
Microsoft Office Excel | =x | |
Microsoft Office Excel Viewer | =2003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1306 has a critical severity level due to its ability to allow arbitrary code execution.
To remediate CVE-2006-1306, users should update Microsoft Excel to the latest version available that addresses this vulnerability.
CVE-2006-1306 affects Microsoft Excel versions 2000, 2002, 2003, and 2004 for Mac, along with Excel Viewer 2003.
Exploitation of CVE-2006-1306 requires user interaction, as it necessitates opening a specially crafted .xls file.
CVE-2006-1306 is associated with attacks that leverage malformed BIFF records in Excel files to execute arbitrary code.