PT-2006-1097 · Microsoft · Office Publisher

Stuart Pearson

·

Published

2006-09-12

·

Updated

2018-10-19

·

CVE-2006-0001

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Publisher versions 2000 through 2003
Description: A stack-based buffer overflow issue allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts. This is related to a remote code execution issue that occurs when Publisher parses a file with a malformed string.
Recommendations: For Microsoft Publisher versions 2000 through 2003, consider avoiding the use of crafted PUB files until a patch is available. As a temporary workaround, restrict the parsing of fonts from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-0001

Affected Products

Office Publisher