cbcvebase.
CVE-2006-0030
published 2006-03-14

CVE-2006-0030: Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute…

PriorityP343medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EXPLOIT
EPSS
39.59%
98.5th percentile
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/27055-1.xls
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/27055-2.xls
  • Trigger is a malformed or corrupted XLS file containing a malformed graphic object; inspect incoming/opened XLS files for anomalous embedded graphic records that may cause memory corruption in Excel.
  • Affected versions span Microsoft Excel 95 through 2004; flag execution of Excel processes spawning child processes or shellcode after opening XLS files from untrusted sources.
  • The vulnerability is triggered when Excel processes malformed/corrupted XLS files; monitor for Excel opening XLS files that contain irregular or oversized graphic record structures.
  • ·Exploitation requires user interaction — the victim must open the malicious XLS file; purely network-based or drive-by exploitation without user assistance is not applicable here.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.