Vulnerabilities > CVE-2005-4131 - Unspecified vulnerability in Microsoft Excel
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 14 |
Exploit-Db
description | Microsoft Excel 95/97/2000/2002/2003/2004 Malformed Range Memory Corruption Vulnerability. CVE-2005-4131 . Dos exploit for windows platform |
id | EDB-ID:26769 |
last seen | 2016-02-03 |
modified | 2005-12-08 |
published | 2005-12-08 |
reporter | fearwall |
source | https://www.exploit-db.com/download/26769/ |
title | Microsoft Excel 95/97/2000/2002/2003/2004 Malformed Range Memory Corruption Vulnerability |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-012.NASL |
description | The remote host is running a version of Microsoft Office that could allow arbitrary code to be run. To succeed, the attacker would have to send a rogue file to a user of the remote computer and have him open it. Then a bug in the font parsing handler would result in code execution. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21078 |
published | 2006-03-14 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21078 |
title | MS06-012: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (905413) |
code |
|
References
- http://www.theage.com.au/news/breaking/excel-flaw-up-for-sale-on-ebay/2005/12/09/1134086783318.html
- http://news.com.com/2061-10789_3-5988086.html
- http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=7203336538
- http://www.dicks-blog.com/archives/2005/12/08/excel-vulnerability-for-sale/
- http://www.osvdb.org/blog/?p=71
- http://www.securityfocus.com/bid/15780
- http://news.zdnet.com/2100-1009_22-5989078.html
- http://informationweek.com/story/showArticle.jhtml?articleID=174910198
- http://securitytracker.com/id?1015333
- http://www.securityfocus.com/news/11363
- http://www.theregister.co.uk/2005/12/10/ebay_pulls_excel_vulnerability_auction/
- http://www.us-cert.gov/cas/techalerts/TA06-073A.html
- http://www.kb.cert.org/vuls/id/642428
- http://securitytracker.com/id?1015766
- http://secunia.com/advisories/19138
- http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm
- http://secunia.com/advisories/19238
- http://securityreason.com/securityalert/584
- http://securityreason.com/securityalert/591
- http://www.vupen.com/english/advisories/2006/0950
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23537
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-012
- http://www.securityfocus.com/archive/1/427698/100/0/threaded
- http://www.securityfocus.com/archive/1/427635/100/0/threaded
- http://www.eweek.com/article2/0%2C1759%2C1899697%2C00.asp?kc=EWRSS03129TX1K0000614