#VU1203 Buffer overflow in Microsoft products - CVE-2006-3647
Published: December 5, 2016
Vulnerability identifier: #VU1203
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2006-3647
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Word Viewer
Microsoft Office for macOS
Microsoft Office
Works Suite
Word Viewer
Microsoft Office for macOS
Microsoft Office
Works Suite
Software vendor:
Microsoft
Microsoft
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The weakness is due to buffer overflow. By persuading the victim to load and open a specially crafted Word document containing a malformed string, a remote attacker can execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
The weakness is due to buffer overflow. By persuading the victim to load and open a specially crafted Word document containing a malformed string, a remote attacker can execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
Remediation
Microsoft Word 2000 - https://www.microsoft.com/downloads/details.aspx?FamilyId=CFC85449-4941-4DA5-A919-1DA388054E83
Microsoft Word 2002 - https://www.microsoft.com/downloads/details.aspx?FamilyId=5652303E-04B3-4713-AF2E-2C8D2450468D
Microsoft Word 2003 - https://www.microsoft.com/downloads/details.aspx?FamilyId=30C516EB-BD63-4248-A34D-47AF7E9EA55A
Microsoft Office Word 2003 Viewer - https://www.microsoft.com/downloads/details.aspx?FamilyId=EB230319-14A5-4206-A601-CF9DDE89352A
Microsoft Works Suite 2004 - https://www.microsoft.com/downloads/details.aspx?FamilyId=5652303E-04B3-4713-AF2E-2C8D2450468D
Microsoft Works Suite 2005 - https://www.microsoft.com/downloads/details.aspx?FamilyId=5652303E-04B3-4713-AF2E-2C8D2450468D
Microsoft Works Suite 2006 - https://www.microsoft.com/downloads/details.aspx?FamilyId=5652303E-04B3-4713-AF2E-2C8D2450468D
Microsoft Office 2004 for Mac - https://www.microsoft.com/mac/
Microsoft Office v. X for Mac - https://www.microsoft.com/mac/
Microsoft Word 2002 - https://www.microsoft.com/downloads/details.aspx?FamilyId=5652303E-04B3-4713-AF2E-2C8D2450468D
Microsoft Word 2003 - https://www.microsoft.com/downloads/details.aspx?FamilyId=30C516EB-BD63-4248-A34D-47AF7E9EA55A
Microsoft Office Word 2003 Viewer - https://www.microsoft.com/downloads/details.aspx?FamilyId=EB230319-14A5-4206-A601-CF9DDE89352A
Microsoft Works Suite 2004 - https://www.microsoft.com/downloads/details.aspx?FamilyId=5652303E-04B3-4713-AF2E-2C8D2450468D
Microsoft Works Suite 2005 - https://www.microsoft.com/downloads/details.aspx?FamilyId=5652303E-04B3-4713-AF2E-2C8D2450468D
Microsoft Works Suite 2006 - https://www.microsoft.com/downloads/details.aspx?FamilyId=5652303E-04B3-4713-AF2E-2C8D2450468D
Microsoft Office 2004 for Mac - https://www.microsoft.com/mac/
Microsoft Office v. X for Mac - https://www.microsoft.com/mac/