This script is Copyright (C) 2006-2012 Tenable Network Security, Inc.
Synopsis :
Arbitrary code can be executed on the remote host through Microsoft
Office.
Description :
The remote host is running a version of Microsoft Office that is
affected by various flaws that may allow arbitrary code to be run.
To succeed, the attacker would have to send a rogue file to a user of
the remote computer and have it open it with Microsoft Word, Excel,
PowerPoint or another Office application.
Solution :
Microsoft has released a set of patches for Office for Mac OS X :
- http://technet.microsoft.com/en-us/security/bulletin/ms06-058
- http://technet.microsoft.com/en-us/security/bulletin/ms06-059
- http://technet.microsoft.com/en-us/security/bulletin/ms06-060
- http://technet.microsoft.com/en-us/security/bulletin/ms06-062
Risk factor :
High / CVSS Base Score : 7.6
(CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 5.6
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false
Family: MacOS X Local Security Checks
Nessus Plugin ID: 22539 (macosx_ms_office_oct2006.nasl)
Bugtraq ID: 18872
20226
20322
20325
20341
20344
20345
20382
20383
20384
20391
CVE ID: CVE-2006-3876
CVE-2006-3877
CVE-2006-4694
CVE-2006-2387
CVE-2006-3431
CVE-2006-3867
CVE-2006-3875
CVE-2006-3647
CVE-2006-4693
CVE-2006-3434
CVE-2006-3650
CVE-2006-3864