[Microsoft Alert] Microsoft Security Bulletin MS06-037
Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (917285)
Issued: July 11, 2006
Version: 1.0
Summary
Who should read this document: Customers who use Microsoft Excel
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should apply the update immediately
Security Update Replacement: This bulletin replaces a prior security update. See the frequently asked questions (FAQ) section of this bulletin for the complete list.
Vulnerability Details:
A remote code execution vulnerability exists in Excel that results from the processing of a malformed SELECTION record. An attacker could exploit the vulnerability by constructing a specially crafted Excel file that could allow remote code execution.
Affected Software:
Microsoft Office 2003 Service Pack 1 or Service Pack 2
Microsoft Office XP Service Pack 3
Microsoft Office 2000 Service Pack 3
Microsoft Office 2004 for Mac
Microsoft Excel v. X for Mac