PT-2006-3440 · Microsoft · Office 2000+3

·

CVE-2006-2492

·

Published

2006-05-19

·

Updated

2025-10-22

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Word versions in Office 2000 SP3 through Office 2003 SP2 Microsoft Works Suites versions through 2006
Description A buffer overflow issue in Microsoft Word allows user-assisted attackers to execute arbitrary code via a malformed object pointer. This was originally reported for a zero-day attack. The issue enables remote code execution when a specially crafted Word file is used.
Recommendations For Microsoft Word versions in Office 2000 SP3 through Office 2003 SP2, update to a version that includes the fix for this issue. For Microsoft Works Suites versions through 2006, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the use of Microsoft Word to minimize the risk of exploitation until a patch is available.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-2492

Affected Products

Office Word
Works Suite
Office 2000
Office 2003