CVE-2006-6456
published 2006-12-11CVE-2006-6456: Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related…
PriorityP272critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
31.45%
98.1th percentile
Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word_viewer | — | — |
| microsoft | works | — | — |
| microsoft | works | — | — |
| microsoft | works | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r6v9-c7q3-4rcq: Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-6456 [CRITICAL] GHSA-r6v9-c7q3-4rcq: Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors
Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
GHSA
GHSA-q2rf-7vjv-wx6h: Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a cra
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-6561 [CRITICAL] GHSA-q2rf-7vjv-wx6h: Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a cra
Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
GHSA
GHSA-p3mj-fq4c-ffqj: Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-5994 [CRITICAL] GHSA-p3mj-fq4c-ffqj: Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v
Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
GHSA
GHSA-gw2r-9wm8-vx4v: Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of servic
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-0515 [CRITICAL] GHSA-gw2r-9wm8-vx4v: Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of servic
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
GHSA
GHSA-fjhq-5r8j-6vg3: Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnera
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-0870 [CRITICAL] GHSA-fjhq-5r8j-6vg3: Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnera
Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
VulnCheck
Word Document Stream Vulnerability
vulncheck·2007·CVSS 9.3
CVE-2007-0870 [CRITICAL] Word Document Stream Vulnerability
Word Document Stream Vulnerability
Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
Affected: Microsoft Word
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024
VulnCheck
Word Malformed Function Vulnerability
vulncheck·2007·CVSS 9.3
CVE-2007-0515 [CRITICAL] Word Malformed Function Vulnerability
Word Malformed Function Vulnerability
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
VulnCheck
Word Malformed Data Structures Vulnerability
vulncheck·2006·CVSS 9.3
CVE-2006-6456 [CRITICAL] Word Malformed Data Structures Vulnerability
Word Malformed Data Structures Vulnerability
Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
VulnCheck
Word Malformed String Vulnerability
vulncheck·2006·CVSS 9.3
CVE-2006-5994 [CRITICAL] Word Malformed String Vulnerability
Word Malformed String Vulnerability
Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
VulnCheck
Microsoft Word Count Vulnerability
vulncheck·2006·CVSS 9.3
CVE-2006-6561 [CRITICAL] Microsoft Word Count Vulnerability
Microsoft Word Count Vulnerability
Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0199.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2006-12/0215.htmlhttp://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspxhttp://isc.sans.org/diary.php?storyid=1925http://secunia.com/advisories/23205http://securitytracker.com/id?1017358http://securitytracker.com/id?1017579http://vil.mcafeesecurity.com/vil/content/v_141056.htmhttp://vil.mcafeesecurity.com/vil/content/v_vul27249.htmhttp://www.kb.cert.org/vuls/id/166700http://www.osvdb.org/30825http://www.securityfocus.com/archive/1/454069/100/0/threadedhttp://www.securityfocus.com/archive/1/454072/100/0/threadedhttp://www.securityfocus.com/archive/1/454093/100/0/threadedhttp://www.securityfocus.com/bid/21518http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlhttp://www.vupen.com/english/advisories/2006/4920http://www.vupen.com/english/advisories/2007/0435https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014https://exchange.xforce.ibmcloud.com/vulnerabilities/30806https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A746http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0199.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2006-12/0215.htmlhttp://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspxhttp://isc.sans.org/diary.php?storyid=1925http://secunia.com/advisories/23205http://securitytracker.com/id?1017358http://securitytracker.com/id?1017579http://vil.mcafeesecurity.com/vil/content/v_141056.htmhttp://vil.mcafeesecurity.com/vil/content/v_vul27249.htmhttp://www.kb.cert.org/vuls/id/166700http://www.osvdb.org/30825http://www.securityfocus.com/archive/1/454069/100/0/threadedhttp://www.securityfocus.com/archive/1/454072/100/0/threadedhttp://www.securityfocus.com/archive/1/454093/100/0/threadedhttp://www.securityfocus.com/bid/21518http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlhttp://www.vupen.com/english/advisories/2006/4920http://www.vupen.com/english/advisories/2007/0435https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014https://exchange.xforce.ibmcloud.com/vulnerabilities/30806https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A746
2006-12-11
Published
Exploited in the wild