PT-2006-2327 · Microsoft · Outlook+6
Published
2006-07-11
·
Updated
2018-10-12
·
CVE-2006-1316
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2003 versions SP1 through SP2
Microsoft Office XP version SP3
Microsoft Office 2000 version SP3
Description
A remote code execution issue exists in Microsoft Office, allowing user-assisted attackers to execute arbitrary code via an Office file with a
malformed string that triggers memory corruption related to record lengths. This can occur when a specially crafted Office file is parsed by any of the affected Office applications. The issue may be exploited through email attachments or files hosted on malicious websites. However, viewing or previewing a malformed email message in an affected version of Outlook does not lead to exploitation.Recommendations
For Microsoft Office 2003 versions SP1 through SP2, update to a version that includes a fix for this issue.
For Microsoft Office XP version SP3, update to a version that includes a fix for this issue.
For Microsoft Office 2000 version SP3, update to a version that includes a fix for this issue.
As a temporary workaround, consider avoiding the use of
malformed strings in Office files until a patch is available. Restrict access to email attachments and files from untrusted sources to minimize the risk of exploitation.Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office 2000
Office 2003
Office Xp
Office
Office Project
Office Visio
Outlook