PT-2006-4723 · Microsoft · Outlook+2
Published
2006-10-10
·
Updated
2018-10-30
·
CVE-2006-3868
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Office versions XP through 2003
Description
A remote code execution issue exists in Microsoft Office, allowing attackers to execute arbitrary code via a malformed Smart Tag when Office opens a specially crafted file. Such files might be included as e-mail attachments or hosted on malicious websites. An attacker could exploit this by constructing a specially crafted Office file, but viewing or previewing a malformed e-mail message in Outlook would not lead to exploitation.
Recommendations
For Microsoft Office versions XP through 2003, consider avoiding the use of Smart Tags until a patch is available. As a temporary workaround, refrain from opening suspicious or specially crafted Office files from untrusted sources. Restrict access to malicious websites and be cautious with e-mail attachments to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office
Office Visio
Outlook