Vulnerabilities > CVE-2006-0033 - Unspecified vulnerability in Microsoft Office 2000/2003/Xp
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-039.NASL |
description | The remote host is running a version of some Microsoft Office filters that are subject to various flaws which could allow arbitrary code to be run. An attacker could use these to execute arbitrary code on this host. To succeed, the attacker would have to send a rogue file to a user of the remote computer and have it import it with Microsoft Office. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22033 |
published | 2006-07-11 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22033 |
title | MS06-039: Vulnerabilities in Microsoft Office Filters Could Allow Remote Code Execution (915384) |
code |
|
Oval
accepted | 2014-03-17T04:00:13.784-04:00 | ||||||||||||||||
class | vulnerability | ||||||||||||||||
contributors |
| ||||||||||||||||
definition_extensions |
| ||||||||||||||||
description | Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed. | ||||||||||||||||
family | windows | ||||||||||||||||
id | oval:org.mitre.oval:def:163 | ||||||||||||||||
status | accepted | ||||||||||||||||
submitted | 2006-07-25T12:05:33 | ||||||||||||||||
title | Microsoft Office Remote Code Execution Using a Malformed PNG Vulnerability | ||||||||||||||||
version | 8 |
References
- http://secunia.com/advisories/21013
- http://secunia.com/advisories/21013
- http://securitytracker.com/id?1016470
- http://securitytracker.com/id?1016470
- http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html
- http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html
- http://www.kb.cert.org/vuls/id/459388
- http://www.kb.cert.org/vuls/id/459388
- http://www.osvdb.org/27147
- http://www.osvdb.org/27147
- http://www.securityfocus.com/bid/18913
- http://www.securityfocus.com/bid/18913
- http://www.us-cert.gov/cas/techalerts/TA06-192A.html
- http://www.us-cert.gov/cas/techalerts/TA06-192A.html
- http://www.vupen.com/english/advisories/2006/2757
- http://www.vupen.com/english/advisories/2006/2757
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-039
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-039
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A163
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A163