First published: Thu Jul 13 2006(Updated: )
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac | =x | |
Microsoft Excel for Mac | =2002-sp1 | |
Microsoft Excel for Mac | =2003-sp1 | |
Microsoft Excel for Mac | =2000 | |
Microsoft Excel Viewer | =2003 | |
Microsoft Excel for Mac | =2000-sp3 | |
Microsoft Excel for Mac | =2002 | |
Microsoft Excel for Mac | =2002-sp3 | |
Microsoft Excel for Mac | =2004 | |
Microsoft Excel for Mac | =2003 | |
Microsoft Excel for Mac | =2000-sr1 | |
Microsoft Excel for Mac | =2002-sp2 | |
Microsoft Excel for Mac | =2000-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1309 is considered a critical vulnerability due to its potential for arbitrary code execution.
To fix CVE-2006-1309, ensure that you update to a patched version of Microsoft Excel that addresses this vulnerability.
CVE-2006-1309 affects Microsoft Excel versions 2000 through 2004 on Mac OS X.
Yes, CVE-2006-1309 can be exploited through user-assisted malicious email attachments containing crafted .xls files.
CVE-2006-1309 can facilitate remote code execution attacks, allowing attackers to execute arbitrary code on affected systems.