CVE-2006-1309: Code Injection
Published Jul 13, 2006
·Updated
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
Affected Software
13 affected components
Microsoft Excel=2000
Microsoft Excel=2000-sp2
Microsoft Excel=2000-sp3
Microsoft Excel=2000-sr1
Microsoft Excel=2002
Microsoft Excel=2002-sp1
Microsoft Excel=2002-sp2
Microsoft Excel=2002-sp3
Microsoft Excel=2003
Microsoft Excel=2003-sp1
Microsoft Excel=2004
Microsoft Excel=x
Microsoft Excel Viewer=2003
Event History
Jul 13, 2006
CVE Published
10:05 PM
Jul 14, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1309?
CVE-2006-1309 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2006-1309?
To fix CVE-2006-1309, ensure that you update to a patched version of Microsoft Excel that addresses this vulnerability.
3
Which versions of Microsoft Excel are affected by CVE-2006-1309?
CVE-2006-1309 affects Microsoft Excel versions 2000 through 2004 on Mac OS X.
4
Can CVE-2006-1309 be exploited via email attachments?
Yes, CVE-2006-1309 can be exploited through user-assisted malicious email attachments containing crafted .xls files.
5
What types of attacks can CVE-2006-1309 facilitate?
CVE-2006-1309 can facilitate remote code execution attacks, allowing attackers to execute arbitrary code on affected systems.