VulnerabilityAnalyzed
CVE-2006-2492
Microsoft Word Malformed Object Pointer Vulnerability
KEVHIGH 8.8EPSS 48.1%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 48.11% probability · 99th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-120
- Affected
- microsoft/office · microsoft/works suite
- Source
- cret@cert.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2006-2492
References
- http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspxBroken Link
- http://isc.sans.org/diary.php?storyid=1345Exploit
- http://isc.sans.org/diary.php?storyid=1346Exploit
- http://secunia.com/advisories/20153Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1016130Broken Link, Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/446012Third Party Advisory, US Government Resource
- http://www.microsoft.com/technet/security/advisory/919637.mspxBroken Link, Patch, Vendor Advisory
- http://www.osvdb.org/25635Broken Link
- http://www.securityfocus.com/bid/18037Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA06-139A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA06-164A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/1872Broken Link
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26556Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068Broken Link
- http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspxBroken Link
- http://isc.sans.org/diary.php?storyid=1345Exploit
- http://isc.sans.org/diary.php?storyid=1346Exploit
- http://secunia.com/advisories/20153Broken Link, Patch, Vendor Advisory
- http://securitytracker.com/id?1016130Broken Link, Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/446012Third Party Advisory, US Government Resource
- http://www.microsoft.com/technet/security/advisory/919637.mspxBroken Link, Patch, Vendor Advisory
- http://www.osvdb.org/25635Broken Link
- http://www.securityfocus.com/bid/18037Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA06-139A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA06-164A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/1872Broken Link
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.