CVE-2006-1301

Description

Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.

Risk Information

Base Score
9.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:F/RL:O/RC:C
EPSS Score
Exploitation Probability
37.943

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Excel 2000 (KB918424)Windows
Security Update for Excel 2002 (KB918420)Windows
Security Update for Excel 2003 (KB918419)Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234