CVE-2006-3014 EXPLOIT
5.1
MEDIUM · CVSS 2.0 · EPSS 30.1% (pctl 98)
Patch early
A public exploit exists.
Description
Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.
Scoring
| CVSS | 5.1 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
| EPSS | 30.1% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-06-22 |
| Last modified | 2026-09-23 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | excel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Office 2003 - Embedded Shockwave Flash Object Security Bypass | 2006-06-22 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-06/0414.html
- http://hackingspirits.com/vuln-rnd/vuln-rnd.html
- http://secunia.com/advisories/21865
- http://secunia.com/advisories/22882
- http://securitytracker.com/id?1016344
- http://www.adobe.com/support/security/bulletins/apsb06-11.html
- http://www.securiteam.com/windowsntfocus/5TP0M0KIUA.html
- http://www.securityfocus.com/bid/18583
- http://www.securityfocus.com/bid/19980
- http://www.us-cert.gov/cas/techalerts/TA06-318A.html
- http://www.vupen.com/english/advisories/2006/3573
- http://www.vupen.com/english/advisories/2006/3577
- http://www.vupen.com/english/advisories/2006/4507
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-069
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27312
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A538
- http://archives.neohapsis.com/archives/fulldisclosure/2006-06/0414.html
- http://hackingspirits.com/vuln-rnd/vuln-rnd.html
- http://secunia.com/advisories/21865
- http://secunia.com/advisories/22882
→ the Explorer · watch your stack · NVD