RULE(RULE ID:710662)

Rule General Information
Release Date: 2014-12-19
Rule Name: Microsoft Excel Crafted URL Unicode Buffer Overflow Vulnerability -4 (CVE-2006-3086)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, aka "Hyperlink COM Object Buffer Overflow Vulnerability."
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks include arbitrary code execution and denial of service.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:ms06-050
SecurityFocusBID:18500
Solutions
Microsoft has released a patch MS06-050 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/bulletin/ms06-050.mspx