CVE-2006-1308: Code Injection
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1308?
CVE-2006-1308 has not been assigned a CVSS score, but it allows for remote code execution, indicating a significant security risk.
How do I fix CVE-2006-1308?
To mitigate CVE-2006-1308, users should upgrade to a patched version of Microsoft Excel that eliminates the vulnerability.
Which versions of Microsoft Excel are affected by CVE-2006-1308?
CVE-2006-1308 affects Microsoft Excel versions 2000, 2002, 2003, and 2004, including their respective service packs.
What type of attack is associated with CVE-2006-1308?
CVE-2006-1308 involves user-assisted attacks, where a malicious .xls file could be executed to run arbitrary code.
Is there a workaround for CVE-2006-1308?
As a workaround for CVE-2006-1308, users should avoid opening unknown or suspicious .xls files until a patch is applied.