CVE-2006-3014
MEDIUM severity · CVSS 5.1 · Improper input validation
5.1CVSS MEDIUM
Summary
Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)30%
AV:N/AC:H/Au:N/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://secunia.com/advisories/21865 ↗
Additional information
- NVD record
- http://secunia.com/advisories/21865Patch
- http://secunia.com/advisories/22882Advisory
- http://securitytracker.com/id?1016344
- http://www.adobe.com/support/security/bulletins/apsb06-11.html
- http://www.securiteam.com/windowsntfocus/5TP0M0KIUA.html
- http://archives.neohapsis.com/archives/fulldisclosure/2006-06/0414.htmlExploit
- http://hackingspirits.com/vuln-rnd/vuln-rnd.htmlExploit
- http://www.securityfocus.com/bid/18583Exploit