CVE-2006-6456
Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 32.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 32.16% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/office · microsoft/word · microsoft/word viewer · microsoft/works
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0199.html
- http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0215.html
- http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspxVendor Advisory
- http://isc.sans.org/diary.php?storyid=1925Vendor Advisory
- http://secunia.com/advisories/23205Vendor Advisory
- http://securitytracker.com/id?1017358
- http://securitytracker.com/id?1017579
- http://vil.mcafeesecurity.com/vil/content/v_141056.htmVendor Advisory
- http://vil.mcafeesecurity.com/vil/content/v_vul27249.htmVendor Advisory
- http://www.kb.cert.org/vuls/id/166700Third Party Advisory, US Government Resource
- http://www.osvdb.org/30825
- http://www.securityfocus.com/archive/1/454069/100/0/threaded
- http://www.securityfocus.com/archive/1/454072/100/0/threaded
- http://www.securityfocus.com/archive/1/454093/100/0/threaded
- http://www.securityfocus.com/bid/21518
- http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/4920
- http://www.vupen.com/english/advisories/2007/0435
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30806
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A746
- http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0199.html
- http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0215.html
- http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspxVendor Advisory
- http://isc.sans.org/diary.php?storyid=1925Vendor Advisory
- http://secunia.com/advisories/23205Vendor Advisory
- http://securitytracker.com/id?1017358
- http://securitytracker.com/id?1017579
- http://vil.mcafeesecurity.com/vil/content/v_141056.htmVendor Advisory
- http://vil.mcafeesecurity.com/vil/content/v_vul27249.htmVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.