CVE-2006-6561
published 2006-12-14CVE-2006-6561: Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC…
PriorityP269critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
40.43%
98.5th percentile
Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word_viewer | — | — |
| microsoft | works | — | — |
| microsoft | works | — | — |
| microsoft | works | — | — |
| openoffice | openoffice | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
offset 0x000027e4 == 41414141
bytes↗
offset 0x00000274 == 00000022
- →The exploit is a two-stage malformed DOC: stage 1 forces execution down a wrong code path; stage 2 (harmless alone) triggers a pointer overwrite when combined. Detection should look for the specific weight/marker field combination rather than either field in isolation. ↗
- →The write primitive follows the formula: destination = ((weight * 4[EDI]) + 4[ECX*4]) + source_memory_offset[ESI]. Monitor for abnormal memory writes in Word/WordViewer processes matching this arithmetic pattern. ↗
- ·Red Hat assessed this CVE (tracked as CVE-2006-6628 in the OOo codebase) as crash-only with no possibility of arbitrary code execution, so detection priority may be lower in OpenOffice.org deployments. ↗
- ·CVE-2006-6561 affects Microsoft Word/WordViewer, while the closely related CVE-2006-6628 affects OpenOffice.org 2.1 — the same PoC file (12122006-djtest.doc) demonstrates both, but they are separate codebases and separate CVEs. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gj93-5m6j-gvr2: Integer overflow in OpenOffice
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-6628 [CRITICAL] GHSA-gj93-5m6j-gvr2: Integer overflow in OpenOffice
Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase.
GHSA
GHSA-q2rf-7vjv-wx6h: Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a cra
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-6561 [CRITICAL] GHSA-q2rf-7vjv-wx6h: Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a cra
Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
GHSA
GHSA-gw2r-9wm8-vx4v: Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of servic
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-0515 [CRITICAL] GHSA-gw2r-9wm8-vx4v: Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of servic
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
GHSA
GHSA-fjhq-5r8j-6vg3: Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnera
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-0870 [CRITICAL] GHSA-fjhq-5r8j-6vg3: Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnera
Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
VulnCheck
Word Document Stream Vulnerability
vulncheck·2007·CVSS 9.3
CVE-2007-0870 [CRITICAL] Word Document Stream Vulnerability
Word Document Stream Vulnerability
Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
Affected: Microsoft Word
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024
VulnCheck
Word Malformed Function Vulnerability
vulncheck·2007·CVSS 9.3
CVE-2007-0515 [CRITICAL] Word Malformed Function Vulnerability
Word Malformed Function Vulnerability
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
VulnCheck
Microsoft Word Count Vulnerability
vulncheck·2006·CVSS 9.3
CVE-2006-6561 [CRITICAL] Microsoft Word Count Vulnerability
Microsoft Word Count Vulnerability
Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
Red Hat
CVE-2006-6628: Integer overflow in OpenOffice
vendor_redhat·CVSS 9.3
CVE-2006-6628 [CRITICAL] CVE-2006-6628: Integer overflow in OpenOffice
Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase.
Statement: Red Hat does not consider this flaw a security issue. This flaw will only crash OpenOffice.org and presents no possibility for arbitrary code execution.
No detection rules found.
No writeups or analysis indexed.
http://blogs.securiteam.com/?p=763http://blogs.technet.com/msrc/archive/2006/12/15/update-on-current-word-vulnerability-reports.aspxhttp://research.eeye.com/html/alerts/zeroday/20061212.htmlhttp://securitytracker.com/id?1017390http://www.infoworld.com/article/06/12/13/HNthirdword_1.htmlhttp://www.kb.cert.org/vuls/id/996892http://www.milw0rm.com/sploits/12122006-djtest.dochttp://www.securityfocus.com/archive/1/454219/30/0/threadedhttp://www.securityfocus.com/bid/21589http://www.vupen.com/english/advisories/2006/4997https://exchange.xforce.ibmcloud.com/vulnerabilities/30885https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A332http://blogs.securiteam.com/?p=763http://blogs.technet.com/msrc/archive/2006/12/15/update-on-current-word-vulnerability-reports.aspxhttp://research.eeye.com/html/alerts/zeroday/20061212.htmlhttp://securitytracker.com/id?1017390http://www.infoworld.com/article/06/12/13/HNthirdword_1.htmlhttp://www.kb.cert.org/vuls/id/996892http://www.milw0rm.com/sploits/12122006-djtest.dochttp://www.securityfocus.com/archive/1/454219/30/0/threadedhttp://www.securityfocus.com/bid/21589http://www.vupen.com/english/advisories/2006/4997https://exchange.xforce.ibmcloud.com/vulnerabilities/30885https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A332
2006-12-14
Published
Exploited in the wild