CVE-2006-2492: Microsoft Word Malformed Object Pointer Vulnerability
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
Other sources
Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.
— CISA
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2492?
CVE-2006-2492 is classified as critical due to its potential to execute arbitrary code on affected systems.
How do I fix CVE-2006-2492?
To fix CVE-2006-2492, users should update their Microsoft Office and Works Suite software to the latest security patches provided by Microsoft.
Which versions of Microsoft Office are affected by CVE-2006-2492?
CVE-2006-2492 affects Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, along with Works Suites through 2006.
What type of vulnerability is CVE-2006-2492?
CVE-2006-2492 is a buffer overflow vulnerability that can be exploited by user-assisted attackers.
Can CVE-2006-2492 be exploited remotely?
CVE-2006-2492 requires user assistance, which means an attacker must convince the user to open a specially crafted document to exploit the vulnerability.