CVE-2006-1318: Code Injection
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1318?
CVE-2006-1318 has a severity rating of critical due to its potential for arbitrary code execution.
How do I fix CVE-2006-1318?
To fix CVE-2006-1318, apply the latest security updates from Microsoft for affected Office products.
What types of Office products are affected by CVE-2006-1318?
CVE-2006-1318 affects Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and Office 2004 for Mac among others.
Can CVE-2006-1318 be exploited remotely?
Yes, CVE-2006-1318 can be exploited remotely through a specially crafted Office document.
What does CVE-2006-1318 allow an attacker to do?
CVE-2006-1318 allows remote attackers to execute arbitrary code on a vulnerable system.