CVE-2006-0031
CVSS5.1
发布时间 :2006-03-14 18:02:00
修订时间 :2011-03-07 00:00:00
NMCOPS    

[原文]Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.


[CNNVD]Microsoft Office Excel畸形记录远程代码执行漏洞(CNNVD-200603-258)

        Microsoft Office Excel是非常流行的电子表格办公软件。
        Microsoft Office Excel在处理畸形Excel文档时存在漏洞,攻击者可能利用此漏洞在用户机器上执行任意代码。
        使用畸形记录的Excel中存在一个远程执行代码漏洞。攻击者可以通过构建特制的Excel文件来利用此漏洞,可能允许远程执行代码。
        Excel在打开".xls"文件时会以0x0e0e0e0e初始化栈缓冲区,但使用的用户提供长度会导致栈溢出。以下代码源于excel v9.0.0.8924:
        >>
        >> .text:3003FE0C movzx eax, word ptr [ebx]
        >> .text:3003FE0F xor ecx, ecx
        >> .text:3003FE11 cmp eax, 0Eh
        >> .text:3003FE14 mov [ebp+var_8], ecx
        >> .text:3003FE17 jg loc_301C01B5
        >>
        >> .text:301C01B5 mov byte ptr [ebp+ecx+var_138], cl
        >> .text:301C01BC inc ecx
        >> .text:301C01BD cmp ecx, 0Eh
        >> .text:301C01C0 jle short loc_301C01B5
        >> .text:301C01C2 cmp ecx, eax
        >> .text:301C01C4 mov [ebp-8], ecx
        >> .text:301C01C7 jg loc_3003FFC9
        >> .text:301C01CD sub eax, ecx
        >> .text:301C01CF lea edi, [ebp+ecx+var_138]
        >> .text:301C01D6 inc eax
        >> .text:301C01D7 mov edx, eax
        >> .text:301C01D9 mov eax, 0E0E0E0Eh
        >> .text:301C01DE mov ecx, edx
        >> .text:301C01E0 mov esi, ecx
        >> .text:301C01E2 shr ecx, 2
        >> .text:301C01E5 rep stosd <== buffer overflow
        
        

- CVSS (基础分值)

CVSS分值: 5.1 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: PARTIAL [可能会导致系统文件被修改]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: HIGH [漏洞利用存在特定的访问条件]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CWE (弱点类目)

CWE-119 [内存缓冲区边界内操作的限制不恰当]

- CPE (受影响的平台与产品)

cpe:/a:microsoft:office:xp:sp3Microsoft Office XP Service Pack 3
cpe:/a:microsoft:office:v.x::mac
cpe:/a:microsoft:office:2000:sp3Microsoft Office 2000 sp3
cpe:/a:microsoft:office:2003:sp2Microsoft Office 2003 sp2
cpe:/a:microsoft:office:2004::macMicrosoft Office 2004 Mac
cpe:/a:microsoft:office:2003:sp1Microsoft Office 2003 sp1

- OVAL (用于检测的技术细节)

oval:org.mitre.oval:def:763Excel 2002 Remote Code Execution via Malformed Record
oval:org.mitre.oval:def:1750Excel 2003 Remote Code Execution via Malformed Record
oval:org.mitre.oval:def:1525Excel Viewer 2003 Remote Code Execution via Malformed Record
oval:org.mitre.oval:def:1327Excel 2000 Remote Code Execution via Malformed Record
*OVAL详细的描述了检测该漏洞的方法,你可以从相关的OVAL定义中找到更多检测该漏洞的技术细节。

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-0031
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200603-258
(官方数据源) CNNVD

- 其它链接及资源

http://www.us-cert.gov/cas/techalerts/TA06-073A.html
(VENDOR_ADVISORY)  CERT  TA06-073A
http://www.kb.cert.org/vuls/id/104302
(VENDOR_ADVISORY)  CERT-VN  VU#104302
http://www.securityfocus.com/bid/17101
(PATCH)  BID  17101
http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx
(PATCH)  MS  MS06-012
http://securitytracker.com/id?1015766
(PATCH)  SECTRACK  1015766
http://secunia.com/advisories/19138
(VENDOR_ADVISORY)  SECUNIA  19138
http://xforce.iss.net/xforce/xfdb/25228
(UNKNOWN)  XF  excel-record-bo(25228)
http://www.vupen.com/english/advisories/2006/0950
(VENDOR_ADVISORY)  VUPEN  ADV-2006-0950
http://www.securityfocus.com/archive/1/archive/1/427699/100/0/threaded
(UNKNOWN)  BUGTRAQ  20060315 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability
http://www.osvdb.org/23902
(UNKNOWN)  OSVDB  23902
http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm
(UNKNOWN)  CONFIRM  http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm
http://securityreason.com/securityalert/589
(UNKNOWN)  SREASON  589
http://secunia.com/advisories/19238
(VENDOR_ADVISORY)  SECUNIA  19238
http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1521.html
(UNKNOWN)  FULLDISC  20060314 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability

- 漏洞信息

Microsoft Office Excel畸形记录远程代码执行漏洞
中危 缓冲区溢出
2006-03-14 00:00:00 2006-08-28 00:00:00
远程  
        Microsoft Office Excel是非常流行的电子表格办公软件。
        Microsoft Office Excel在处理畸形Excel文档时存在漏洞,攻击者可能利用此漏洞在用户机器上执行任意代码。
        使用畸形记录的Excel中存在一个远程执行代码漏洞。攻击者可以通过构建特制的Excel文件来利用此漏洞,可能允许远程执行代码。
        Excel在打开".xls"文件时会以0x0e0e0e0e初始化栈缓冲区,但使用的用户提供长度会导致栈溢出。以下代码源于excel v9.0.0.8924:
        >>
        >> .text:3003FE0C movzx eax, word ptr [ebx]
        >> .text:3003FE0F xor ecx, ecx
        >> .text:3003FE11 cmp eax, 0Eh
        >> .text:3003FE14 mov [ebp+var_8], ecx
        >> .text:3003FE17 jg loc_301C01B5
        >>
        >> .text:301C01B5 mov byte ptr [ebp+ecx+var_138], cl
        >> .text:301C01BC inc ecx
        >> .text:301C01BD cmp ecx, 0Eh
        >> .text:301C01C0 jle short loc_301C01B5
        >> .text:301C01C2 cmp ecx, eax
        >> .text:301C01C4 mov [ebp-8], ecx
        >> .text:301C01C7 jg loc_3003FFC9
        >> .text:301C01CD sub eax, ecx
        >> .text:301C01CF lea edi, [ebp+ecx+var_138]
        >> .text:301C01D6 inc eax
        >> .text:301C01D7 mov edx, eax
        >> .text:301C01D9 mov eax, 0E0E0E0Eh
        >> .text:301C01DE mov ecx, edx
        >> .text:301C01E0 mov esi, ecx
        >> .text:301C01E2 shr ecx, 2
        >> .text:301C01E5 rep stosd <== buffer overflow
        
        

- 公告与补丁

        目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
        http://www.microsoft.com/technet/security/Bulletin/MS06-012.mspx#E4EAE

- 漏洞信息 (F48190)

msExcel-again.txt (PacketStormID:F48190)
2006-07-12 00:00:00
OXYin  nevisnetworks.com
advisory,remote,code execution
CVE-2006-1308,CVE-2006-0031
[点击下载]

A remote code execution vulnerability exists in Excel using a FNGROUPCOUNT value. An attacker could exploit the vulnerability by constructing a specially crafted Excel file that could allow remote code execution. Affected products include Microsoft Office 2000 SP3, XP SP3, 2003 SP1/SP2, Microsoft Works Suites, Microsoft Office X for Mac, Microsoft Office 2004 for Mac.

------=_Part_5447_16401853.1152673884138
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Microsoft Excel Could Allow Remote Code Execution by Malformed FNGROUPCOUNT
value Vulnerability

By OYXin( xin.ouyang at google mail ) of Nevis Labs
http://www.nevisnetworks.com


Vendor
Microsoft Inc.

Products affected:
Microsoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 1 or Service Pack 2
Microsoft Works Suites
Microsoft Office X for Mac
Microsoft Office 2004 for Mac


Overview:
A remote code execution vulnerability exists in Excel using a FNGROUPCOUNT
value. An attacker could exploit the vulnerability by constructing a
specially crafted Excel file that could allow remote code execution.


Details:
The vulnerable code is similar to MS06-012(CVE-2006-0031) which found by
eyas.

==============================================================================
eax=0e0e0e0e ebx=0000fff1 ecx=00002241 edx=0000000f esi=00138964
edi=0013ffff
eip=30093040 esp=0013794c ebp=001388e4 iopl=0         nv up ei pl nz na
po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000
efl=00010206
*** ERROR: Symbol file could not be found.  Defaulted to export
symbols for Excel.EXE -
Excel!Ordinal41+0x93040:
30093040 f3ab             rep     stosd
es:0013ffff=74634100

Excel!Ordinal41+0x9302e:
3009302e 5c               pop     esp
3009302f f3ffff           rep     ???
30093032 8bd9             mov     ebx,ecx
30093034 c1e902           shr     ecx,0x2
30093037 8d7c1520         lea     edi,[ebp+edx+0x20]
3009303b b80e0e0e0e       mov     eax,0xe0e0e0e
30093040 f3ab             rep     stosd

> 0:000> g
> (b98.5fc): Access violation - code c0000005 (first chance) First
> chance exceptions are reported before any exception handling.
> This exception may be expected and handled.
> eax=00000000 ebx=00000000 ecx=0e0e0e0e edx=7c9037d8 esi=00000000
> edi=00000000
> eip=0e0e0e0e esp=0013757c ebp=0013759c iopl=0         nv up ei pl zr na
> po nc
> cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000
> efl=00010246
> 0e0e0e0e ??               ???
==============================================================================

POC:
No POC will be supplied

Fix:
Microsoft has released an update for Microsoft Office which isset to address
this issue. This can be downloaded from:
http://www.microsoft.com/technet/security/bulletin/MS06-037.mspx


Vendor Response:
2006.04.12 Vendor notified via secure@microsoft.com
2006.04.12 Vendor responded
2006.07.11 Vendor released MS06-037 patch
2006.07.12 Advisory released


Reference:
1. http://sc.openoffice.org/excelfileformat.pdf
2. http://www.microsoft.com/technet/security/bulletin/MS06-037.mspx
3. http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1308
4. http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031


Greetings to Nevis lab guys and 0x557 guys :)

------=_Part_5447_16401853.1152673884138
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Microsoft Excel Could Allow Remote Code Execution by Malformed FNGROUPCOUNT value Vulnerability<br><br>By OYXin( xin.ouyang at google mail ) of Nevis Labs<br><a href="http://www.nevisnetworks.com">http://www.nevisnetworks.com
</a><br><br><br>Vendor<br>Microsoft Inc.<br><br>Products affected:<br>Microsoft Office 2000 Service Pack 3<br>Microsoft Office XP Service Pack 3<br>Microsoft Office 2003 Service Pack 1 or Service Pack 2<br>Microsoft Works Suites
<br>Microsoft Office X for Mac <br>Microsoft Office 2004 for Mac <br><br><br>Overview:<br>A remote code execution vulnerability exists in Excel using a FNGROUPCOUNT value. An attacker could exploit the vulnerability by constructing a specially crafted Excel file that could allow remote code execution.
<br><br><br>Details:<br>The vulnerable code is similar to MS06-012(CVE-2006-0031) which found by eyas.<br><br>==============================================================================<br>eax=0e0e0e0e ebx=0000fff1 ecx=00002241 edx=0000000f esi=00138964 
<br>edi=0013ffff<br>eip=30093040 esp=0013794c ebp=001388e4 iopl=0         nv up ei pl nz na <br>po nc<br>cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             <br>efl=00010206<br>*** ERROR: Symbol file could not be found.  Defaulted to export 
<br>symbols for Excel.EXE -<br>Excel!Ordinal41+0x93040:<br>30093040 f3ab             rep     stosd                  <br>es:0013ffff=74634100<br><br>Excel!Ordinal41+0x9302e:<br>3009302e 5c               pop     esp<br>3009302f f3ffff           rep     ???
<br>30093032 8bd9             mov     ebx,ecx<br>30093034 c1e902           shr     ecx,0x2<br>30093037 8d7c1520         lea     edi,[ebp+edx+0x20]<br>3009303b b80e0e0e0e       mov     eax,0xe0e0e0e<br>30093040 f3ab             rep     stosd
<br><br>> 0:000> g<br>> (b98.5fc): Access violation - code c0000005 (first chance) First <br>> chance exceptions are reported before any exception handling.<br>> This exception may be expected and handled.<br>
> eax=00000000 ebx=00000000 ecx=0e0e0e0e edx=7c9037d8 esi=00000000 <br>> edi=00000000<br>> eip=0e0e0e0e esp=0013757c ebp=0013759c iopl=0         nv up ei pl zr na <br>> po nc<br>> cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             
<br>> efl=00010246<br>> 0e0e0e0e ??               ???<br>==============================================================================<br><br>POC:<br>No POC will be supplied<br><br>Fix:<br>Microsoft has released an update for Microsoft Office which isset to address this issue. This can be downloaded from:
<br><a href="http://www.microsoft.com/technet/security/bulletin/MS06-037.mspx">http://www.microsoft.com/technet/security/bulletin/MS06-037.mspx</a><br><br><br>Vendor Response:<br>2006.04.12 Vendor notified via <a href="mailto:secure@microsoft.com">
secure@microsoft.com</a> <br>2006.04.12 Vendor responded<br>2006.07.11 Vendor released MS06-037 patch<br>2006.07.12 Advisory released<br><br><br>Reference:<br>1. <a href="http://sc.openoffice.org/excelfileformat.pdf">http://sc.openoffice.org/excelfileformat.pdf
</a><br>2. <a href="http://www.microsoft.com/technet/security/bulletin/MS06-037.mspx">http://www.microsoft.com/technet/security/bulletin/MS06-037.mspx</a><br>3. <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1308">
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1308</a><br>4. <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031">http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031</a><br><br>
<br>Greetings to Nevis lab guys and 0x557 guys :)<br><br>

------=_Part_5447_16401853.1152673884138--

    

- 漏洞信息 (F44663)

Technical Cyber Security Alert 2006-73A (PacketStormID:F44663)
2006-03-15 00:00:00
CERT,US-CERT  us-cert.gov
advisory,remote,denial of service,arbitrary,vulnerability
CVE-2005-4131,CVE-2006-0009,CVE-2006-0028,CVE-2006-0029,CVE-2006-0030,CVE-2006-0031
[点击下载]

Technical Cyber Security Alert TA06-073A - Microsoft has released updates that address critical vulnerabilities in Microsoft Office and Excel. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



                        National Cyber Alert System

                Technical Cyber Security Alert TA06-073A


Microsoft Office and Excel Vulnerabilities

   Original release date: March 14, 2006
   Last revised: --
   Source: US-CERT


Systems Affected

     * Microsoft Office for Windows and Mac OS X
     * Microsoft Excel for Windows and Mac OS X
     * Microsoft Works Suite for Windows

   For more complete information, refer to the Microsoft Security
   Bulletin Summary for March 2006.


Overview

   Microsoft has released updates that address critical vulnerabilities
   in Microsoft Office and Excel. Exploitation of these vulnerabilities
   could allow a remote, unauthenticated attacker to execute arbitrary
   code or cause a denial of service on a vulnerable system.


I. Description

   Microsoft Security Bulletin Summary for March 2006 addresses
   vulnerabilities in Microsoft Office and Excel. Further information is
   available in the following US-CERT Vulnerability Notes:

   VU#339878 - Microsoft Excel malformed parsing format file memory
   corruption vulnerability 

   Microsoft Excel contains a memory corruption vulnerability. This
   vulnerability may allow a remote attacker to execute arbitrary code on
   a vulnerable system.
   (CVE-2006-0028)

   VU#104302 - Microsoft Excel malformed record memory corruption
   vulnerability 

   Microsoft Excel fails to properly validate records. This vulnerability
   may allow a remote attacker to execute arbitrary code on a vulnerable
   system.
   (CVE-2006-0031)

   VU#123222 - Microsoft Excel malformed graphic memory corruption
   vulnerability 

   Microsoft Excel fails to properly validate graphics. This
   vulnerability may allow a remote attacker to execute arbitrary code on
   a vulnerable system.
   (CVE-2006-0030)

   VU#235774 - Microsoft Excel malformed description memory corruption
   vulnerability 

   Microsoft Excel fails to properly validate the description field. This
   vulnerability may allow a remote attacker to execute arbitrary code on
   a vulnerable system.
   (CVE-2006-0029)

   VU#642428 - Microsoft Excel fails to properly perform range validation
   when parsing document files 

   Microsoft Excel contains an error in range validation, which may allow
   a remote unauthenticated, attacker to execute arbitrary code on a
   vulnerable system.
   (CVE-2005-4131)

   VU#682820 - Microsoft Office routing slip buffer overflow 

   Microsoft Office contains a buffer overflow in the parsing of routing
   slips, which may allow an attacker to execute arbitrary code on a
   vulnerable system.
   (CVE-2006-0009)


II. Impact

   A remote, unauthenticated attacker could execute arbitrary code with
   the privileges of the user. If the user is logged on with
   administrative privileges, the attacker could take complete control of
   an affected system. An attacker may also be able to cause a denial of
   service.


III. Solution

Apply Updates

   Microsoft has provided the updates for these vulnerabilities in the
   Security Bulletins and on the Microsoft Update site.


Workarounds

   Please see the following US-CERT Vulnerability Notes for workarounds.


Appendix A. References

     * Microsoft Security Bulletin Summary for March 2006 -
       <http://www.microsoft.com/technet/security/bulletin/ms06-mar.mspx>

     * US-CERT Vulnerability Note VU#339878 -
       <http://www.kb.cert.org/vuls/id/339878>

     * US-CERT Vulnerability Note VU#104302 -
       <http://www.kb.cert.org/vuls/id/104302>

     * US-CERT Vulnerability Note VU#123222 -
       <http://www.kb.cert.org/vuls/id/123222>

     * US-CERT Vulnerability Note VU#235774 -
       <http://www.kb.cert.org/vuls/id/235774>

     * US-CERT Vulnerability Note VU#642428 -
       <http://www.kb.cert.org/vuls/id/642428>

     * US-CERT Vulnerability Note VU#682820 -
       <http://www.kb.cert.org/vuls/id/682820>

     * CVE-2005-4131 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4131>

     * CVE-2006-0009 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0009>

     * CVE-2006-0028 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0028>

     * CVE-2006-0029 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0029>

     * CVE-2006-0030 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0030>

     * CVE-2006-0031 -
       <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031>

     * Microsoft Update - <https://update.microsoft.com/microsoftupdate>


 ____________________________________________________________________
 
   The most recent version of this document can be found at:

     <http://www.us-cert.gov/cas/techalerts/TA06-073A.html>
 ____________________________________________________________________

   Feedback can be directed to US-CERT Technical Staff. Please send
   email to <cert@cert.org> with "TA06-073A Feedback VU#339878" in the
   subject.
 ____________________________________________________________________

   For instructions on subscribing to or unsubscribing from this
   mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
 ____________________________________________________________________

   Produced 2006 by US-CERT, a government organization.

   Terms of use:

     <http://www.us-cert.gov/legal.html>
 ____________________________________________________________________


Revision History

   March 14, 2006: Initial release
  
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iQEVAwUBRBdHxH0pj593lg50AQKjmwgA09ePMKZtjsxkwWaWMSFxtqGZaeV1hHby
LBApam/YAuNpmLZKzwz36quzlbceDcSeBQKKbvgqhi/Cm4Sjsywczay0agHsdXiv
dzwQCAeE0+5JA2kidsdQV9u+X866hfDq63oXy3nef/x1RPOBvNSOb8FnG1yvMCwn
965R6SUbtrA/4HRcEmVH+8dciSnARh90rcIPN6EorC7mCdXykk2YDs0MX8nuT+fl
HeHn06kvTkmJbRNZ/xq7LyGIVeuQ7Xqv1fCiqywNdJUxHg1YPmBIPqfY3e6dcqE1
rS6ithE6u9GlDMTYbTLhL3+JGE4IiIRuZL10z37x+w07AHSFuTHfWQ==
=3xcR
-----END PGP SIGNATURE-----
    

- 漏洞信息

23902
Microsoft Office Excel Malformed Record Arbitrary Code Execution
Remote / Network Access Input Manipulation
Loss of Integrity
Exploit Unknown

- 漏洞描述

A remote overflow exists in Excel. The product fails to check the length of a buffer of a record resulting in a stack overflow. With a specially crafted .xls file, an attacker can cause arbitrary code execution resulting in a loss of integrity.

- 时间线

2006-03-14 Unknow
Unknow Unknow

- 解决方案

Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a patch to address this vulnerability.

- 相关参考

- 漏洞作者

- 漏洞信息

Microsoft Excel Malformed Record Remote Code Execution Vulnerability
Boundary Condition Error 17101
Yes No
2006-03-14 12:00:00 2006-04-06 10:53:00
Discovery is credited to Eyas of the XFOCUS Security Team.

- 受影响的程序版本

Nortel Networks Optivity Telephony Manager (OTM)
Nortel Networks MCS 5200 3.0
Nortel Networks MCS 5100 3.0
Nortel Networks IP softphone 2050
Nortel Networks Enterprise Network Management System
Microsoft Excel x for Mac 0
Microsoft Excel Viewer 2003 0
+ Microsoft Office 2003 SP1
+ Microsoft Office 2003 SP1
+ Microsoft Office 2003 SP1
Microsoft Excel 2004 for Mac 0
Microsoft Excel 2003 SP1
+ Microsoft Office 2003 SP1
Microsoft Excel 2003
+ Microsoft Office 2003 0
Microsoft Excel 2002 SP3
+ Microsoft Office XP SP3
Microsoft Excel 2002 SP2
+ Microsoft Office XP SP2
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home SP1
- Microsoft Windows XP Home
- Microsoft Windows XP Professional SP1
- Microsoft Windows XP Professional
Microsoft Excel 2002 SP1
+ Microsoft Office XP SP1
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Terminal Services SP2
- Microsoft Windows 2000 Terminal Services SP1
- Microsoft Windows 2000 Terminal Services
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
- Microsoft Windows XP Professional
Microsoft Excel 2002
+ Microsoft Office XP
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95 SR2
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0
Microsoft Excel 2000 SR1
+ Microsoft Office 2000 SP1
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Terminal Services SP2
- Microsoft Windows 2000 Terminal Services SP1
- Microsoft Windows 2000 Terminal Services
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
Microsoft Excel 2000 SP3
+ Microsoft Office 2000 SP3
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home SP1
- Microsoft Windows XP Home
- Microsoft Windows XP Professional SP1
- Microsoft Windows XP Professional
Microsoft Excel 2000 SP2
+ Microsoft Office 2000 SP2
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Terminal Services SP2
- Microsoft Windows 2000 Terminal Services SP1
- Microsoft Windows 2000 Terminal Services
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
Microsoft Excel 2000
+ Microsoft Office 2000
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP6
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0
Avaya Modular Messaging (MAS) 3.0

- 漏洞讨论

Microsoft Excel is prone to a remote code-execution vulnerability. This issue may be triggered when a Excel document with malformed record data is opened.

- 漏洞利用

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com

- 解决方案


Microsoft has released fixes to address this vulnerability in supported versions of the affected software.

Avaya has released advisory ASA-2006-069 to identify vulnerable Avaya products. Avaya advises customers to apply patches released by Microsoft. Please see the references for more information.


Microsoft Excel 2000 SR1

Microsoft Excel x for Mac 0

Microsoft Excel 2003 SP1

Microsoft Excel 2002 SP2

Microsoft Excel 2000 SP2

Microsoft Excel 2003

Microsoft Excel 2004 for Mac 0

Microsoft Excel 2002 SP3

Microsoft Excel 2002 SP1

Microsoft Excel 2002

Microsoft Excel 2000

Microsoft Excel 2000 SP3

Microsoft Excel Viewer 2003 0

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站