PT-2006-4368 · Microsoft · Office Word+1

Kcope

·

Published

2006-07-10

·

Updated

2018-10-30

·

CVE-2006-3493

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Office versions prior to the fixed version
Description A buffer overflow issue exists in the LsCreateLine function, affecting Microsoft Word and possibly other products in Microsoft Office. This issue can be exploited by remote user-assisted attackers via a crafted Word DOC or other Office file type, leading to a denial of service (crash). Initially, it was reported that this issue could allow code execution, but Microsoft and the original researcher later confirmed that code execution is not possible.
Recommendations For Microsoft Office versions prior to the fixed version, update to the fixed version to resolve the issue. As a temporary workaround, consider avoiding the use of crafted Word DOC or other Office file types that could trigger the buffer overflow in the LsCreateLine function.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3493

Affected Products

Office
Office Word