CVE-2006-2388: Code Injection
Published Jul 13, 2006
·Updated
Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
Affected Software
13 affected components
Microsoft Excel=x
Microsoft Excel=2002-sp1
Microsoft Excel=2003-sp1
Microsoft Excel=2000
Microsoft Excel Viewer=2003
Microsoft Excel=2000-sp3
Microsoft Excel=2002
Microsoft Excel=2002-sp3
Microsoft Excel=2004
Microsoft Excel=2003
Microsoft Excel=2000-sr1
Microsoft Excel=2002-sp2
Microsoft Excel=2000-sp2
Remediation
Patch Available
Event History
Jul 13, 2006
CVE Published
09:05 PM
Jul 14, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2388?
CVE-2006-2388 is considered critical due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2006-2388?
To mitigate CVE-2006-2388, users should upgrade to a patched version of Microsoft Excel.
3
Which versions are affected by CVE-2006-2388?
CVE-2006-2388 affects multiple versions including Excel 2000 through 2004 for Mac and Excel Viewer 2003.
4
Who can exploit CVE-2006-2388?
User-assisted attackers can exploit CVE-2006-2388 by convincing victims to open a specially crafted Excel file.
5
What are the consequences of CVE-2006-2388?
Exploitation of CVE-2006-2388 can lead to unauthorized code execution and potential compromise of sensitive data.