Overview
A vulnerability in Microsoft Word could allow an attacker to compromise a vulnerable system.
Description
Data used by Microsoft Word to construct a destination address for a memory copy routine is embedded within a Word document itself. If an attacker constructs a Word document with a specially crafted value used to build this destination address, then that attacker may be able to overwrite arbitrary memory. An attacker could trigger this vulnerability by convincing a user to open a specially crafted Word document. |
Impact
The specific consequences of this vulnerability are unclear, but may include execution of arbitrary code and denial of service. |
Solution
Apply Update for Microsoft |
Do not open untrusted Word documents |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was publicly disclosed by disco.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-6561 |
Severity Metric: | 11.00 |
Date Public: | 2006-12-12 |
Date First Published: | 2006-12-14 |
Date Last Updated: | 2007-02-13 19:15 UTC |
Document Revision: | 23 |