First published: Sat May 20 2006(Updated: )
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2000-sp3 | |
Microsoft Office | =2003-sp1 | |
Microsoft Office | =2003-sp2 | |
Microsoft Office | =xp-sp3 | |
Microsoft Works Suite | >=2000<=2006 | |
Microsoft Word for Android | =2003 | |
Microsoft Word for Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2492 is classified as critical due to its potential to execute arbitrary code on affected systems.
To fix CVE-2006-2492, users should update their Microsoft Office and Works Suite software to the latest security patches provided by Microsoft.
CVE-2006-2492 affects Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, along with Works Suites through 2006.
CVE-2006-2492 is a buffer overflow vulnerability that can be exploited by user-assisted attackers.
CVE-2006-2492 requires user assistance, which means an attacker must convince the user to open a specially crafted document to exploit the vulnerability.