Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (917285)
Microsoft Security Bulletin MS06-037
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should apply the update immediately
This Security Bulletin covers multiple CVE items as indicated below:
CVE-2006-1301 - Microsoft Excel Malformed SELECTION record vulnerability
This update resolves several public, privately reported, and newly discovered vulnerabilities. All of these state that a remote code execution vulnerability exists in Excel dealing with each of the identified items. The only workaround suggested and tested is to NOT open attachments from untrusted sources. I guess that means, PATCH.
When using vulnerable versions of Office, if a user were logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the client workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Jul 11th 2006
1 decade ago