Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (917285)Microsoft Security Bulletin MS06-037 Impact of Vulnerability: Remote Code Execution Maximum Severity Rating: Critical Recommendation: Customers should apply the update immediately This Security Bulletin covers multiple CVE items as indicated below: CVE-2006-1301 - Microsoft Excel Malformed SELECTION record vulnerability This update resolves several public, privately reported, and newly discovered vulnerabilities. All of these state that a remote code execution vulnerability exists in Excel dealing with each of the identified items. The only workaround suggested and tested is to NOT open attachments from untrusted sources. I guess that means, PATCH. Microsoft states: When using vulnerable versions of Office, if a user were logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the client workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. |
Deborah 279 Posts ISC Handler Jul 11th 2006 |
Thread locked Subscribe |
Jul 11th 2006 1 decade ago |
Sign Up for Free or Log In to start participating in the conversation!