Intrusion Prevention

MS.Excel.Style.Record.Code.Execution

Description

This indicates an attempt to exploit a buffer overflow in Microsoft Excel running on Simplified Chinese, Traditional Chinese, Japanese, or Korean versions of Microsoft Windows.
The vulnerability may allow an attacker to execute arbitrary code. It can be exploited via a maliciously crafted spreadsheet that triggers the overflow when a user attempts to repair the document or select the "Style" option.

Affected Products

Microsoft Excel Viewer 2003
Microsoft Excel 2003 SP1
Microsoft Excel 2003
Microsoft Excel 2002 SP1 - SP3
Microsoft Excel 2002
Microsoft Excel 2000 SR1
Microsoft Excel 2000 SP2 - SP3
Microsoft Excel 2000

Impact

System compromise: remote code execution.

Recommended Actions

As of September 26, 2006, Fortinet is unaware of any vendor supplied patches for this issue. If you have more recent information, please contact us at "vulnwatch" at fortinet.com.
Do not open files from untrusted sources.
Verify all machines are running the latest security patches from Microsoft.

CVE References

CVE-2006-3431