Vulnerabilities > CVE-2006-2389 - Unspecified vulnerability in Microsoft Office 2000/2003/Xp
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description | Microsoft Office 2000/2002 Property Code Execution Vulnerability. CVE-2006-2389. Remote exploit for windows platform |
id | EDB-ID:28198 |
last seen | 2016-02-03 |
modified | 2006-07-11 |
published | 2006-07-11 |
reporter | anonymous |
source | https://www.exploit-db.com/download/28198/ |
title | Microsoft Office 2000/2002 Property Code Execution Vulnerability |
Nessus
NASL family MacOS X Local Security Checks NASL id MACOSX_MS_06-037.NASL description The remote host is running a version of Microsoft Office that is affected by various flaws that may allow arbitrary code to be run. To succeed, the attacker would have to send a rogue file to a user of the remote computer and have it open it with Microsoft Excel or another Office application. last seen 2020-03-18 modified 2006-07-11 plugin id 22025 published 2006-07-11 reporter This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/22025 title MS06-037 / MS06-038: Vulnerabilities in Microsoft Excel and Office Could Allow Remote Code Execution (917284 / 917285) (Mac OS X) NASL family Windows : Microsoft Bulletins NASL id SMB_NT_MS06-038.NASL description The remote host is running a version of Microsoft Office that could allow arbitrary code to be run on this host. To succeed, the attacker would have to send a rogue file to a user of the remote computer and have him open it with Microsoft Office. last seen 2020-06-01 modified 2020-06-02 plugin id 22032 published 2006-07-11 reporter This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/22032 title MS06-038: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (917284)
Oval
accepted | 2012-05-28T04:01:37.400-04:00 | ||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||
description | Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316. | ||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:279 | ||||||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||||||
submitted | 2006-07-25T12:05:33 | ||||||||||||||||||||||||||||||||
title | Microsoft Office Property Vulnerability | ||||||||||||||||||||||||||||||||
version | 13 |
Packetstorm
data source | https://packetstormsecurity.com/files/download/93302/mop-exec.txt |
id | PACKETSTORM:93302 |
last seen | 2016-12-05 |
published | 2010-08-30 |
reporter | Abhishek Lyall |
source | https://packetstormsecurity.com/files/93302/Microsoft-Office-Property-Code-Execution.html |
title | Microsoft Office Property Code Execution |
Seebug
bulletinFamily exploit description No description provided by source. id SSV:81775 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-81775 title Microsoft Office 2000/2002 Property Code Execution Vulnerability bulletinFamily exploit description No description provided by source. id SSV:20083 last seen 2017-11-19 modified 2010-09-02 published 2010-09-02 reporter Root source https://www.seebug.org/vuldb/ssvid-20083 title Microsoft Office Property Code Execution exploit (CVE-2006-2389)
References
- http://secunia.com/advisories/21012
- http://securitytracker.com/id?1016469
- http://www.kb.cert.org/vuls/id/409316
- http://www.osvdb.org/27149
- http://www.securityfocus.com/bid/18911
- http://www.us-cert.gov/cas/techalerts/TA06-192A.html
- http://www.vupen.com/english/advisories/2006/2756
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-038
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27609
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A279