Overview
A remote code execution vulnerability in Microsoft Word can allow a remote attacker to execute arbitrary code via a specially crafted mail merge file.
Description
Microsoft Word contains a remote code execution vulnerability that can be exploited when a specially crafted mail merge file is opened by Word. |
Impact
A remote attacker who can successfully convince the user to open the specially crafted mail merge file may be able to execute arbitrary code with the privileges of the local user. |
Solution
Apply an update
|
Workaround
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Microsoft Security for reporting this vulnerability in Microsoft Security Bulletin MS06-060.
This document was written by Katie Steiner.
Other Information
CVE IDs: | CVE-2006-3651 |
Severity Metric: | 2.52 |
Date Public: | 2006-10-10 |
Date First Published: | 2006-10-12 |
Date Last Updated: | 2006-10-12 14:57 UTC |
Document Revision: | 17 |