Vulnerability Note VU#580036
Microsoft Office fails to properly handle malformed strings
Overview
Microsoft Office fails to properly handle specially crafted strings. This vulnerability could allow a remote attacker to execute arbitrary code.
Description
Microsoft Office applications fail to properly validate strings. When an Office document containing malformed string is opened with an Office application, system memory can be corrupted in a way that may allow an attacker to execute arbitrary code. More information, including a list of affected Office applications, is available in Microsoft Security Bulletin MS06-038. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code. |
Solution
Apply a patch from Microsoft |
Do not access Office documents from untrusted sources
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Affected | - | 11 Jul 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
Credit
This vulnerability was reported in Microsoft Security Bulletin MS06-038.
This document was written by Jeff Gennari.
Other Information
- CVE IDs: CVE-2006-1316
- Date Public: 11 Jul 2006
- Date First Published: 11 Jul 2006
- Date Last Updated: 13 Jul 2006
- Severity Metric: 16.03
- Document Revision: 14
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.