7.5
CVSSv2

CVE-2006-3431

Published: 07/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted malicious users to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced prior to 20060707, including CVE-2006-3059 and CVE-2006-3086.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft excel

Exploits

source: wwwsecurityfocuscom/bid/18872/info Microsoft Excel is prone to a remote code-execution vulnerability Successfully exploiting this issue allows attackers to execute arbitrary code in the context of targeted users A proof-of-concept malicious code named 'TrojanHongmosa' is actively exploiting this vulnerability, which results i ...