SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2006-2492

Microsoft Word Malformed Object Pointer Vulnerability

KEVHIGH 8.8EPSS 48.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
48.11% probability · 99th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022
Weakness
CWE-120
Affected
microsoft/office · microsoft/works suite
Source
cret@cert.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2006-2492

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.