CVE-2006-2387
⚪ Do wiadomości
Nieokreślona podatność w Microsoft Excel umożliwia wykonanie dowolnego kodu przez złośliwe pliki XLS.
CVSS
5.1
EPSS
41.2%
Exploit
none
Vendor
microsoft
Opis źródłowy (NVD)
Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 41.2% |
| Opublikowano (NVD) | 2006-10-10 22:07:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-04-23 00:35:47 UTC |
Referencje
- http://securitytracker.com/id?1017031 (secure@microsoft.com) [Third Party Advisory, VDB Entry]
- http://www.kb.cert.org/vuls/id/706668 (secure@microsoft.com) [Third Party Advisory, US Government Resource]
- http://www.securityfocus.com/archive/1/448147/100/0/threaded (secure@microsoft.com)
- http://www.securityfocus.com/archive/1/449179/100/0/threaded (secure@microsoft.com)
- http://www.securityfocus.com/bid/20344 (secure@microsoft.com) [Third Party Advisory, VDB Entry]
- http://www.vupen.com/english/advisories/2006/3978 (secure@microsoft.com) [Vendor Advisory]
- http://www.zerodayinitiative.com/advisories/ZDI-06-033.html (secure@microsoft.com) [Third Party Advisory, VDB Entry]
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-059 (secure@microsoft.com)
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A570 (secure@microsoft.com) [Third Party Advisory]