PT-2006-2327 · Microsoft · Outlook+6

Published

2006-07-11

·

Updated

2018-10-12

·

CVE-2006-1316

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office 2003 versions SP1 through SP2 Microsoft Office XP version SP3 Microsoft Office 2000 version SP3
Description A remote code execution issue exists in Microsoft Office, allowing user-assisted attackers to execute arbitrary code via an Office file with a malformed string that triggers memory corruption related to record lengths. This can occur when a specially crafted Office file is parsed by any of the affected Office applications. The issue may be exploited through email attachments or files hosted on malicious websites. However, viewing or previewing a malformed email message in an affected version of Outlook does not lead to exploitation.
Recommendations For Microsoft Office 2003 versions SP1 through SP2, update to a version that includes a fix for this issue. For Microsoft Office XP version SP3, update to a version that includes a fix for this issue. For Microsoft Office 2000 version SP3, update to a version that includes a fix for this issue. As a temporary workaround, consider avoiding the use of malformed strings in Office files until a patch is available. Restrict access to email attachments and files from untrusted sources to minimize the risk of exploitation.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-1316

Affected Products

Office 2000
Office 2003
Office Xp
Office
Office Project
Office Visio
Outlook