PT-2006-3440 · Microsoft · Office 2000+3

Andreas Marx

+1

·

Published

2006-05-19

·

Updated

2025-10-22

·

CVE-2006-2492

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Word versions in Office 2000 SP3 through Office 2003 SP2 Microsoft Works Suites versions through 2006
Description A buffer overflow issue in Microsoft Word allows user-assisted attackers to execute arbitrary code via a malformed object pointer. This was originally reported for a zero-day attack. The issue enables remote code execution when a specially crafted Word file is used.
Recommendations For Microsoft Word versions in Office 2000 SP3 through Office 2003 SP2, update to a version that includes the fix for this issue. For Microsoft Works Suites versions through 2006, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the use of Microsoft Word to minimize the risk of exploitation until a patch is available.

Exploit

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2006-2492

Affected Products

Office Word
Works Suite
Office 2000
Office 2003