First published: Wed Dec 06 2006(Updated: )
Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Works Suite | =2006 | |
Microsoft Office | =2004 | |
Microsoft Office Word | =2000 | |
Microsoft Office | =xp-sp3 | |
Microsoft Office | =2003-sp2 | |
Microsoft Office Word | =2003 | |
Microsoft Works Suite | =2005 | |
Microsoft Office Word | =2002 | |
Microsoft Office Word Viewer | =2003 | |
Microsoft Works Suite | =2004 | |
Microsoft Office | =2000-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5994 is considered a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-5994, apply the latest security updates provided by Microsoft for the affected software versions.
CVE-2006-5994 affects Microsoft Word versions 2000, 2002, 2003, and 2004 for Mac.
If unable to update, consider restricting access to affected applications or using alternative applications until updates can be applied.
CVE-2006-5994 can be exploited remotely via a specially crafted Word document.