CVE-2006-2492

CVE Published 2006-05-20
Related CWE(s) CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Related Vendor(s) microsoft
Related Product(s) office, works_suite, word
Exploitation Reported (CISA KEV) 2022-06-08
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References