CVE-2006-3864: Code Injection
Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3864?
CVE-2006-3864 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2006-3864?
To fix CVE-2006-3864, update Microsoft Office and related applications to the latest service pack or security update.
What software is affected by CVE-2006-3864?
CVE-2006-3864 affects Microsoft Office 2000, 2003, and XP, as well as Microsoft Project and Visio 2002.
What types of files can exploit CVE-2006-3864?
CVE-2006-3864 can be exploited through malformed .DOC, .PPT, and .XLS files.
What attack vector is used in CVE-2006-3864?
CVE-2006-3864 allows attackers to execute arbitrary code via user-assisted methods.