// For flags

CVE-2006-2388

Microsoft Office Excel File Rebuilding Code Execution Vulnerability

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.

Microsoft Office Excel 2000 hasta la versión 2004 permite a atacantes asistidos por el usuario ejecutar código arbitrario a través de comentarios de celdas mal formadas, lo que conduce a modificación de "desplazamiento de datos críticos" durante el proceso de reconstrucción.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file.
The specific flaw exists within the rebuilding of malformed cell comments. When Excel encounters a malformed record it attempts to rebuild the broken meta-data. A flaw in this rebuilding process allows the user to specify critical data offsets eventually leading to code execution with the credentials of the current user.

*Credits: Arnaud Dovi 'class101' http://heapoverflow.com
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-05-15 CVE Reserved
  • 2006-07-11 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-11-01 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2000
Search vendor "Microsoft" for product "Excel" and version "2000"
-
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2000
Search vendor "Microsoft" for product "Excel" and version "2000"
sp2
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2000
Search vendor "Microsoft" for product "Excel" and version "2000"
sp3
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2000
Search vendor "Microsoft" for product "Excel" and version "2000"
sr1
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2002
Search vendor "Microsoft" for product "Excel" and version "2002"
-
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2002
Search vendor "Microsoft" for product "Excel" and version "2002"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2002
Search vendor "Microsoft" for product "Excel" and version "2002"
sp2
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2002
Search vendor "Microsoft" for product "Excel" and version "2002"
sp3
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2003
Search vendor "Microsoft" for product "Excel" and version "2003"
-
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2003
Search vendor "Microsoft" for product "Excel" and version "2003"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
2004
Search vendor "Microsoft" for product "Excel" and version "2004"
mac_os_x
Affected
Microsoft
Search vendor "Microsoft"
Excel
Search vendor "Microsoft" for product "Excel"
x
Search vendor "Microsoft" for product "Excel" and version "x"
mac_os_x
Affected
Microsoft
Search vendor "Microsoft"
Excel Viewer
Search vendor "Microsoft" for product "Excel Viewer"
2003
Search vendor "Microsoft" for product "Excel Viewer" and version "2003"
-
Affected