Vulnerabilities > CVE-2006-3493 - Unspecified vulnerability in Microsoft Office 2000/2003/Xp

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
microsoft
exploit available

Summary

Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.

Vulnerable Configurations

Part Description Count
Application
Microsoft
12

Exploit-Db

descriptionMicrosoft Word 2000/2003 Unchecked Boundary Condition Vulnerability. CVE-2006-3493. Dos exploit for windows platform
idEDB-ID:2001
last seen2016-01-31
modified2006-07-10
published2006-07-10
reporternaveed afzal
sourcehttps://www.exploit-db.com/download/2001/
titleMicrosoft Word 2000/2003 Unchecked Boundary Condition Vulnerability