Description
Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
Affected products
- Microsoft / office2000 – 2000
- Microsoft / office2003 – 2003
- Microsoft / office2004 – 2004
- Microsoft / officexp – xp
- Microsoft / Word2000 – 2000
- Microsoft / Word2002 – 2002
- Microsoft / Word2003 – 2003
- Microsoft / word_viewer2003 – 2003
- Microsoft / works2004 – 2004
- Microsoft / works2005 – 2005
- Microsoft / works2006 – 2006
References
- MISChttp://www.securityfocus.com/bid/21589
- MISChttp://blogs.technet.com/msrc/archive/2006/12/15/update-on-current-word-vulnerability-reports.aspx
- MISChttp://securitytracker.com/id?1017390
- MISChttp://www.infoworld.com/article/06/12/13/HNthirdword_1.html
- MISChttp://www.milw0rm.com/sploits/12122006-djtest.doc
- MISChttp://www.securityfocus.com/archive/1/454219/30/0/threaded
- MISChttp://research.eeye.com/html/alerts/zeroday/20061212.html
- MISChttp://www.kb.cert.org/vuls/id/996892
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/4997
- MISChttp://blogs.securiteam.com/?p=763
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/30885
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A332