Vulnerability Note VU#996892
Microsoft Word malformed pointer vulnerability
Overview
A vulnerability in Microsoft Word could allow an attacker to compromise a vulnerable system.
Description
Data used by Microsoft Word to construct a destination address for a memory copy routine is embedded within a Word document itself. If an attacker constructs a Word document with a specially crafted value used to build this destination address, then that attacker may be able to overwrite arbitrary memory. An attacker could trigger this vulnerability by convincing a user to open a specially crafted Word document. |
Impact
The specific consequences of this vulnerability are unclear, but may include execution of arbitrary code and denial of service. |
Solution
Apply Update for Microsoft |
Do not open untrusted Word documents |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Affected | - | 13 Feb 2007 |
| OpenOffice.org | Affected | - | 02 Jan 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://blogs.technet.com/msrc/archive/2006/12/15/update-on-current-word-vulnerability-reports.aspx
- http://research.eeye.com/html/alerts/zeroday/20061212.html
- http://www.microsoft.com/technet/security/bulletin/ms07-014.mspx
Credit
This vulnerability was publicly disclosed by disco.
This document was written by Jeff Gennari.
Other Information
- CVE IDs: CVE-2006-6561
- Date Public: 12 Dec 2006
- Date First Published: 14 Dec 2006
- Date Last Updated: 13 Feb 2007
- Severity Metric: 11.00
- Document Revision: 18
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.