New Search

Excel-Flash Arbitrary Code Execution Vulnerability

oval:org.mitre.oval:def:538

Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object which is automatically executed when the user opens the spreadsheet.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows XP
Class:
vulnerability
Reference(s):
  • CVE-2006-3014
Product(s):
  • Flash Player