Overview
Microsoft Office fails to properly parse strings. This vulnerability could allow a remote attacker to execute arbitrary code.
Description
Microsoft Office applications fail to properly parse strings. When an Office document containing malformed string is opened with an Office application, system memory can be corrupted in a way that may allow an attacker to execute arbitrary code. More information, including a list of affected Office applications, is available in Microsoft Security Bulletin MS06-038. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code. |
Solution
Apply a patch from Microsoft |
Do not access Office documents from untrusted sources
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported in Microsoft Security Bulletin MS06-038. Microsoft credits Elia Florio of Symantec with providing information regarding this vulnerability.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-1540 |
Severity Metric: | 33.67 |
Date Public: | 2006-07-11 |
Date First Published: | 2006-07-11 |
Date Last Updated: | 2006-07-11 21:09 UTC |
Document Revision: | 8 |