CVE-2006-7037: Medium severity Microsoft Windows 2000 vulnerability
Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the "is-locked" attribute, and (4) view locked data, which is stored in plaintext.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7037?
CVE-2006-7037 is a moderate severity vulnerability that allows local users to bypass security features in Mathcad.
How do I fix CVE-2006-7037?
To fix CVE-2006-7037, ensure you update to a version of Mathcad that is not vulnerable, specifically versions after 13.1.
What software is affected by CVE-2006-7037?
CVE-2006-7037 affects Mathsoft Mathcad versions 12, 13, and 13.1.
What can attackers do with CVE-2006-7037?
Attackers can bypass password protection by editing the XML representation of a worksheet in Mathcad.
Is Mathcad 14 or later affected by CVE-2006-7037?
No, Mathcad 14 and later versions are not affected by CVE-2006-7037.