Mathcad 12 through 13.1 allows local users to bypass the...
Vulnerability Description
Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the "is-locked" attribute, and (4) view locked data, which is stored in plaintext.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-7037
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27118
- http://securityreason.com/securityalert/2305
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27116
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27115
- http://www.securityfocus.com/archive/1/436441/30/4560/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27117
Affected Vendor
mathsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.