9.3
CVSSv2

CVE-2006-1540

Published: 30/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted malicious users to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt. NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode "Sheet Name" string.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft office

microsoft office 2003

microsoft office 2000

microsoft office xp

microsoft office 2004

microsoft office v.x

Exploits

# Full archive at githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/1615rar (excel_03262006rar) Topic : Microsoft Office 2002 - Excel/Powerpoint/Word 10026140 => 11056120 Date : 02/12/2006 Author : posidron <posidron@tripbitnet> Table of Contens ================ - Some Excel Inf ...