CVE-2006-4695: Code Injection
Published Dec 31, 2006
·Updated
Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability."
Affected Software
1 affected component
Microsoft Office Web Components=2000
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2006
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 12, 2008
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4695?
CVE-2006-4695 is considered to have a high severity due to the potential for remote code execution.
2
How do I fix CVE-2006-4695?
To fix CVE-2006-4695, apply the latest security updates from Microsoft for Office Web Components.
3
What types of attacks are associated with CVE-2006-4695?
CVE-2006-4695 is associated with user-assisted remote attacks that can execute arbitrary code via crafted URLs.
4
Which software is affected by CVE-2006-4695?
CVE-2006-4695 affects Microsoft Office Web Components version 2000.
5
What are the potential consequences of exploiting CVE-2006-4695?
Exploiting CVE-2006-4695 could allow attackers to take control of the affected system and execute unwanted commands.