CVE-2006-3650
Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 38.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 38.66% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- microsoft/office
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/22339Vendor Advisory
- http://securitytracker.com/id?1017034Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/534276Third Party Advisory, US Government Resource
- http://www.osvdb.org/29428Broken Link
- http://www.securityfocus.com/archive/1/448151/100/0/threaded
- http://www.securityfocus.com/archive/1/449179/100/0/threaded
- http://www.securityfocus.com/bid/20383Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/3981Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-06-034.htmlThird Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-062
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A222Third Party Advisory
- http://secunia.com/advisories/22339Vendor Advisory
- http://securitytracker.com/id?1017034Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/534276Third Party Advisory, US Government Resource
- http://www.osvdb.org/29428Broken Link
- http://www.securityfocus.com/archive/1/448151/100/0/threaded
- http://www.securityfocus.com/archive/1/449179/100/0/threaded
- http://www.securityfocus.com/bid/20383Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/3981Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-06-034.htmlThird Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-062
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A222Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.