CVE-2006-3876
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 11.46% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- microsoft/office
- Source
- secure@microsoft.com
References
- http://securitytracker.com/id?1017030Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/938196Third Party Advisory, US Government Resource
- http://www.osvdb.org/29447Broken Link
- http://www.securityfocus.com/archive/1/449179/100/0/threaded
- http://www.securityfocus.com/bid/20322Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/3977Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-058
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A453Third Party Advisory
- http://securitytracker.com/id?1017030Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/938196Third Party Advisory, US Government Resource
- http://www.osvdb.org/29447Broken Link
- http://www.securityfocus.com/archive/1/449179/100/0/threaded
- http://www.securityfocus.com/bid/20322Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/3977Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-058
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A453Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.