PT-2006-1120 · Microsoft · Office+4

Dejun

·

Publicado

2006-03-14

·

Atualizado

2018-10-12

·

CVE-2006-0029

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Excel versions 2000 through 2003 Microsoft Office version 2000 SP3
Description: A remote code execution issue exists in Excel due to a malformed description, which can lead to memory corruption. This allows an attacker to execute arbitrary code by constructing a specially crafted Excel file. The issue can be exploited by user-assisted attackers, enabling remote code execution.
Recommendations: For Microsoft Excel versions 2000 through 2003, consider avoiding the use of malformed descriptions in Excel files until a patch is available. For Microsoft Office version 2000 SP3, restrict the opening of specially crafted Excel files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0029

Produtos afetados

Office Excel
Office
Office Powerpoint
Office Word
Outlook