First published: Fri Sep 19 2014(Updated: )
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =x | |
Microsoft Office | =2004 | |
Microsoft Office | =xp-sp3 | |
Microsoft Office | =2000-sp1 | |
Microsoft Office | =2000-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1318 has a severity rating of critical due to its potential for arbitrary code execution.
To fix CVE-2006-1318, apply the latest security updates from Microsoft for affected Office products.
CVE-2006-1318 affects Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and Office 2004 for Mac among others.
Yes, CVE-2006-1318 can be exploited remotely through a specially crafted Office document.
CVE-2006-1318 allows remote attackers to execute arbitrary code on a vulnerable system.