PT-2006-3440 · Microsoft · Office 2000+3
Andreas Marx
+1
·
Published
2006-05-19
·
Updated
2025-10-22
·
CVE-2006-2492
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Word versions in Office 2000 SP3 through Office 2003 SP2
Microsoft Works Suites versions through 2006
Description
A buffer overflow issue in Microsoft Word allows user-assisted attackers to execute arbitrary code via a malformed object pointer. This was originally reported for a zero-day attack. The issue enables remote code execution when a specially crafted Word file is used.
Recommendations
For Microsoft Word versions in Office 2000 SP3 through Office 2003 SP2, update to a version that includes the fix for this issue.
For Microsoft Works Suites versions through 2006, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting the use of Microsoft Word to minimize the risk of exploitation until a patch is available.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Word
Works Suite
Office 2000
Office 2003