CVE-2006-2492
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
- Affected products
- Office Word, Works Suite, Office 2000, Office 2003
- Microsoft Office
- = 2000, 2003, xp
- Microsoft Works Suite
- ≤ 2006
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 48.4% (99th percentile)
- Weakness
- CWE-120
- NVD status
- Analyzed
- Published
- 2006-05-20
CVE-2006-2492 at NVD
1 known exploit for CVE-2006-2492
Proof-of-concept code and exploit modules indexed by Sploitus