CVE-2006-2492
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Word Malformed Object Pointer Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 48% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-120
מוצרים מושפעים
microsoft: office; microsoft: works suite
קישורים
- http://secunia.com/advisories/20153 Broken LinkPatchVendor Advisory
- http://www.microsoft.com/technet/security/advisory/919637.mspx Broken LinkPatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-… PatchVendor Advisory
- http://secunia.com/advisories/20153 Broken LinkPatchVendor Advisory
- http://www.microsoft.com/technet/security/advisory/919637.mspx Broken LinkPatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-… PatchVendor Advisory
- http://www.securityfocus.com/bid/18037 Broken LinkPatchThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/18037 Broken LinkPatchThird Party AdvisoryVDB Entry
- http://isc.sans.org/diary.php?storyid=1345 Exploit
- http://isc.sans.org/diary.php?storyid=1346 Exploit