Overview
Microsoft Word 2000 contains a memory corruption vulnerability. This vulnerability could allow a remote, unauthenticated attacker to execute arbitrary code with the privileges of the user running Word 2000.
Description
Microsoft Word 2000 fails to properly handle malformed records leading to memory corruption. For more information refer to Microsoft Security Bulletin MS06-060. Note that we have received reports that this vulnerability is actively being exploited. |
Impact
By convincing a user to open a specially crafted Word document, an attacker could execute arbitrary code with the privileges of the user running Word 2000. If the user is logged in with administrative privileges, the attacker could take complete control of a vulnerable system. |
Solution
Apply an update |
Do not open untrusted Word documents
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by Juha-Matti Laurio.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-4534 |
Severity Metric: | 25.06 |
Date Public: | 2006-09-05 |
Date First Published: | 2006-09-07 |
Date Last Updated: | 2006-10-10 19:51 UTC |
Document Revision: | 34 |