CVE-2006-3059
UnknownEPSS 41.11%
Last modified
CVE-2006-3059 is a vulnerability of currently unknown severity. Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.. EPSS estimates a 41.11% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Excel | 2000 |
| Microsoft | Excel | 2002 |
| Microsoft | Excel | 2003 |
| Microsoft | Excel | 2004 |
| Microsoft | Excel Viewer | 2003 |
References
- http://secunia.com/advisories/20686Vendor Advisory
- http://www.kb.cert.org/vuls/id/802324US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA06-167A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA06-192A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/2361Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2755Vendor Advisory
- http://secunia.com/advisories/20686Vendor Advisory
- http://www.kb.cert.org/vuls/id/802324US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA06-167A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA06-192A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/2361Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2755Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3059?
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
How severe is CVE-2006-3059?
Severity scoring for CVE-2006-3059 is pending analysis. The EPSS model estimates a 41.11% probability of exploitation in the next 30 days.
How do I fix CVE-2006-3059?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-3052Cross-site scripting (XSS) vulnerability in Event Registrati…
- CVE-2006-3053PHP remote file inclusion vulnerability in common.php in PHO…
- CVE-2006-3054Multiple SQL injection vulnerabilities in VBZooM 1.11 allow …
- CVE-2006-3055Multiple SQL injection vulnerabilities in VBZooM 1.02 allow …
- CVE-2006-3056SQL injection vulnerability in language.php in VBZooM 1.01 a…
- CVE-2006-3057Unspecified vulnerability in NetworkManager daemon for DHCP …
- CVE-2006-3060Cross-site scripting (XSS) vulnerability in P.A.I.D 2.2 allo…
- CVE-2006-3061Multiple cross-site scripting (XSS) vulnerabilities in 5 Sta…
- CVE-2006-3062Cross-site scripting (XSS) vulnerability in index.php in myP…
- CVE-2006-3063Multiple cross-site scripting (XSS) vulnerabilities in myPHP…
- CVE-2006-3064SQL injection vulnerability in the add_hit function in inclu…
- CVE-2006-3065SQL injection vulnerability in engine/shards/blog.php in blu…
Are you affected by CVE-2006-3059?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
