CVE-2006-0028
Microsoft Excel File Format Parsing Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file.
The specific flaw exists within the parsing of the BIFF file format used by Microsoft Excel. During the processing of malformed BOOLERR records, user-supplied data may be insecurely referenced thereby leading to the eventual execution of arbitrary code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2005-11-30 CVE Reserved
- 2006-03-14 CVE Published
- 2024-07-03 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/583 | Third Party Advisory | |
http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm | X_refsource_confirm | |
http://www.kb.cert.org/vuls/id/339878 | Third Party Advisory | |
http://www.osvdb.org/23899 | Vdb Entry | |
http://www.securityfocus.com/archive/1/427632/100/0/threaded | Mailing List | |
http://www.us-cert.gov/cas/techalerts/TA06-073A.html | Third Party Advisory | |
http://www.zerodayinitiative.com/advisories/ZDI-06-004.html | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25225 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1158 | Signature | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1411 | Signature | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1509 | Signature | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1635 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/19138 | 2018-10-19 | |
http://securitytracker.com/id?1015766 | 2018-10-19 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/19238 | 2018-10-19 | |
http://www.vupen.com/english/advisories/2006/0950 | 2018-10-19 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-012 | 2018-10-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2000 Search vendor "Microsoft" for product "Excel" and version "2000" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2002 Search vendor "Microsoft" for product "Excel" and version "2002" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2003 Search vendor "Microsoft" for product "Excel" and version "2003" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2004 Search vendor "Microsoft" for product "Excel" and version "2004" | mac_os_x |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | x Search vendor "Microsoft" for product "Excel" and version "x" | mac_os_x |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Search vendor "Microsoft" for product "Office" | 2000 Search vendor "Microsoft" for product "Office" and version "2000" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Search vendor "Microsoft" for product "Office" | 2003 Search vendor "Microsoft" for product "Office" and version "2003" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Search vendor "Microsoft" for product "Office" | 2003 Search vendor "Microsoft" for product "Office" and version "2003" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Search vendor "Microsoft" for product "Office" | 2004 Search vendor "Microsoft" for product "Office" and version "2004" | mac |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Search vendor "Microsoft" for product "Office" | v.x Search vendor "Microsoft" for product "Office" and version "v.x" | mac |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Search vendor "Microsoft" for product "Office" | xp Search vendor "Microsoft" for product "Office" and version "xp" | sp3 |
Affected
|