=====================================================================
                                    CERT-Renater

                         Note d'Information No. 2006/VULN400
_____________________________________________________________________

DATE                      : 12/07/2006

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Microsoft Excel 2000 et plus

======================================================================

MS06-037 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution
CVE-2006-3059 CVE-2006-2388 CVE-2006-1309
CVE-2006-1308 CVE-2006-1306 CVE-2006-1304
CVE-2006-1302 CVE-2006-1301

Affected Software:
    - Microsoft Office 2003 Service Pack 1 or Service Pack 2
         - Microsoft Excel 2003
         - Microsoft Excel Viewer 2003
    - Microsoft Office XP Service Pack 3
         - Microsoft Excel 2002
    - Microsoft Office 2000 Service Pack 3
         - Microsoft Excel 2000
    - Microsoft Office 2004 for Mac
         - Microsoft Excel 2004 for Mac
    - Microsoft Office v. X for Mac
         - Microsoft Excel v. X for Mac

Remote code execution vulnerabilities exist in Excel that result from the
processing of a malformed file, malformed SELECTION, COLINFO or OBJECT record,
malformed LABEL record file or malformed FNGROUPCOUNT value file. An attacker
could exploit these vulnerabilities by constructing a specially crafted Excel
file that could allow remote code execution.

If a user were logged on with administrative user rights, an attacker who
successfully exploited these vulnerabilities could take complete control of an
affected system. An attacker could then install programs; view, change, or
delete data; or create new accounts with full user rights. Users whose
accounts are configured to have fewer user rights on the system could be less
affected than users who operate with administrative user rights.

Mitigating Factors
- ------------------
    - An attacker who successfully exploited these vulnerabilities could gain
      the same user rights as the local user. Users whose accounts are
      configured to have fewer user rights on the system could be less impacted
      than users who operate with administrative user rights.

    - On Outlook 2002 and Outlook 2003, the vulnerabilities could not be
      exploited automatically through e-mail. For an attack to be successful a
      user must accept a prompt confirming that they Open, Save or Cancel the
      attachment that is sent in an e-mail message before the exploit could
      occur.

    - In a Web-based attack scenario, an attacker could host a Web site that
      contains a Web page that is used to exploit these vulnerabilities. In
      addition, compromised Web sites and Web sites that accept or host
      user-provided content or advertisements could contain specially crafted
      content that could exploit these vulnerabilities. In all cases, however,
      an attacker would have no way to force users to visit these Web sites.
      Instead, an attacker would have to persuade users to visit the Web site,
      typically by getting them to click a link in an e-mail message or instant
      messenger message that takes users to the attacker's Web site.

    Note: Office 2000 does not prompt the user to Open, Save, or Cancel before
          opening a document.

Workarounds
- -----------
Microsoft has tested the following workarounds. While these workarounds will
not correct the underlying vulnerability, they help block known attack vectors.

Do not open or save Microsoft Excel files that you receive from un-trusted
sources or that you receive unexpectedly from trusted sources.

This vulnerability could be exploited when a user opens a file.

           =========================================================
           Les serveurs de référence du CERT-Renater
           http://www.urec.fr/securite
           http://www.cru.fr/securite
           http://www.renater.fr
           =========================================================
           + CERT-RENATER          | tel : 01-53-94-20-44          +
           + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
           + 75013 Paris           | email: certsvp@renater.fr     +
           =========================================================

