peter bassill · operator
$ cve CVE-2005-4131 JSON

CVE-2005-4131 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 31.1% (pctl 98)

Patch early

A public exploit exists.

Description

Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS31.11% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-09
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftexcel

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD