CVE-2006-2387
Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 12.62% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/office
- Source
- secure@microsoft.com
References
- http://securitytracker.com/id?1017031Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/706668Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/448147/100/0/threaded
- http://www.securityfocus.com/archive/1/449179/100/0/threaded
- http://www.securityfocus.com/bid/20344Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/3978Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-06-033.htmlThird Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A570Third Party Advisory
- http://securitytracker.com/id?1017031Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/706668Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/448147/100/0/threaded
- http://www.securityfocus.com/archive/1/449179/100/0/threaded
- http://www.securityfocus.com/bid/20344Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/3978Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-06-033.htmlThird Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A570Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.