PT-2006-3350 · Microsoft · Office 2003+5

Published

2006-07-11

·

Updated

2018-10-12

·

CVE-2006-2389

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office 2003 versions SP1 through SP2 Microsoft Office XP version SP3 Microsoft Office 2000 version SP3
Description A remote code execution issue exists in Office, allowing attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths. This can be exploited when a malformed property included in an Office file is parsed by any of the affected Office applications. Such a property might be included in an email attachment processed by one of the affected applications or hosted on a malicious web site. An attacker could exploit the issue by constructing a specially crafted Office file that could allow remote code execution.
Recommendations For Microsoft Office 2003 versions SP1 through SP2, update to a version that includes the fix for this issue. For Microsoft Office XP version SP3, update to a version that includes the fix for this issue. For Microsoft Office 2000 version SP3, update to a version that includes the fix for this issue. As a temporary workaround, consider avoiding the use of Office files from untrusted sources until a patch is available.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-2389

Affected Products

Office 2000
Office 2003
Office Xp
Office
Office Project
Office Visio