CVE Vulnerabilities

CVE-2006-7037

Published: Feb 23, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the is-locked attribute, and (4) view locked data, which is stored in plaintext.

Affected Software

NameVendorStart VersionEnd Version
Windows_2000Microsoft**
Windows_2003_serverMicrosoftsp2 (including)sp2 (including)
Windows_95Microsoft**
Windows_98Microsoft**
Windows_98seMicrosoft**
Windows_meMicrosoft**
Windows_ntMicrosoft4.0 (including)4.0 (including)
Windows_xpMicrosoft**

References