Junglewise Threat Intelligence

CVE-2006-2492: Microsoft Word Malformed Object Pointer Vulnerability

CVE-2006-2492 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Microsoft Word. Vendors: Microsoft.

Executive brief

A buffer overflow vulnerability in Microsoft Word and Microsoft Works Suites allows remote attackers to execute arbitrary code via a malformed object pointer. This is a user-assisted vulnerability that was originally exploited as a zero-day attack in 2006.

Affected products

  • Microsoft Word 2000 SP3
  • Microsoft Word XP SP3
  • Microsoft Word 2003 SP1, SP2
  • Microsoft Works Suites through 2006

Timeline

  • 2006-05-19: disclosed: Originally reported by ISC as a zero-day attack.
  • 2006-05-19: exploited: Zero-day attack reported.
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats