CVE-2006-3059
published 2006-06-17CVE-2006-3059: Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE…
PriorityP270critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
41.11%
98.5th percentile
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel_viewer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\xd9\xee\xd9\x74\x24\xf4\x5b\x31\xc9\xb1\x5e\x81\x73\x17\x4f\x85\x2f\x98
bytes↗
\x77\xF5\x76\xDE
bytes↗
\x77\xF9\x2A\x9B
bytes↗
D0 CF 11 E0 A1 B1 1A E1
- →The shellcode opens a bind shell on TCP port 4444. Monitor for unexpected outbound/inbound connections on port 4444 following Excel process execution. ↗
- →The exploit targets Excel 2000 on Windows XP SP1 and Windows 2000 SP4. The return address used is a pop/pop/ret gadget in NTDLL.DLL at 0x77F576DE (XP SP1 English) or jmp ebx at 0x77F92A9B (Win2K SP4 English). These specific addresses in stack frames during Excel crashes are strong indicators of exploitation. ↗
- →CVE-2006-3059 is a distinct vulnerability from CVE-2006-3086 (HrShellOpenWithMonikerDisplayName buffer overflow in hlink.dll). Do not conflate the two; CVE-2006-3059 relates to malformed URL handling within Excel itself. ↗
- ·The buff_size (0x152E) and seh_off (4855) values are approximate and variant across different Excel versions; analysts should verify offsets in a debugger for other targets. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m272-v93v-8ggr: Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYL
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-3431 [CRITICAL] GHSA-m272-v93v-8ggr: Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYL
Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.
GHSA
GHSA-43vm-vj9c-qch2: Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-3086 [CRITICAL] CWE-119 GHSA-43vm-vj9c-qch2: Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink
Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.
GHSA
GHSA-qfq4-v5cr-vvr4: Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-3059 [CRITICAL] GHSA-qfq4-v5cr-vvr4: Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
VulnCheck
Microsoft Excel Malformed file Vulnerability
vulncheck·2006·CVSS 9.3
CVE-2006-3059 [CRITICAL] Microsoft Excel Malformed file Vulnerability
Microsoft Excel Malformed file Vulnerability
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
Affected: Microsoft Excel
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-037
No detection rules found.
No writeups or analysis indexed.
http://blogs.securiteam.com/?p=451http://blogs.technet.com/msrc/archive/2006/06/16/436174.aspxhttp://isc.sans.org/diary.php?storyid=1420http://secunia.com/advisories/20686http://securitytracker.com/id?1016316http://www.kb.cert.org/vuls/id/802324http://www.osvdb.org/26527http://www.securityfocus.com/archive/1/437636/100/0/threadedhttp://www.securityfocus.com/archive/1/437936/100/0/threadedhttp://www.securityfocus.com/bid/18422http://www.us-cert.gov/cas/techalerts/TA06-167A.htmlhttp://www.us-cert.gov/cas/techalerts/TA06-192A.htmlhttp://www.vupen.com/english/advisories/2006/2361http://www.vupen.com/english/advisories/2006/2755https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-037https://exchange.xforce.ibmcloud.com/vulnerabilities/27179https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A537http://blogs.securiteam.com/?p=451http://blogs.technet.com/msrc/archive/2006/06/16/436174.aspxhttp://isc.sans.org/diary.php?storyid=1420http://secunia.com/advisories/20686http://securitytracker.com/id?1016316http://www.kb.cert.org/vuls/id/802324http://www.osvdb.org/26527http://www.securityfocus.com/archive/1/437636/100/0/threadedhttp://www.securityfocus.com/archive/1/437936/100/0/threadedhttp://www.securityfocus.com/bid/18422http://www.us-cert.gov/cas/techalerts/TA06-167A.htmlhttp://www.us-cert.gov/cas/techalerts/TA06-192A.htmlhttp://www.vupen.com/english/advisories/2006/2361http://www.vupen.com/english/advisories/2006/2755https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-037https://exchange.xforce.ibmcloud.com/vulnerabilities/27179https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A537
2006-06-17
Published
Exploited in the wild