cbcvebase.
CVE-2006-3590
published 2006-07-14

CVE-2006-3590: mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a…

PriorityP267medium5.1CVSS 2.0
AVNACHAuNCPIPAP
ITWVulnCheck KEV
Exploited in the wild
EPSS
14.26%
96.2th percentile
mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftpowerpoint
microsoftpowerpoint
microsoftpowerpoint

CVSS provenance

nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.