Vulnerabilities > CVE-2006-3649 - Unspecified vulnerability in Microsoft Visual Basic 6.2/6.3/6.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-047.NASL |
description | The remote host is running a version of Microsoft Visual Basic for Applications that is vulnerable to a buffer overflow when handling malformed documents. An attacker may exploit this flaw to execute arbitrary code on this host by sending a malformed file to a user of the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22189 |
published | 2006-08-08 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22189 |
title | MS06-047: Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution (921645) |
code |
|
Oval
accepted | 2015-08-10T04:01:08.526-04:00 | ||||||||||||
class | vulnerability | ||||||||||||
contributors |
| ||||||||||||
definition_extensions |
| ||||||||||||
description | Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents. | ||||||||||||
family | windows | ||||||||||||
id | oval:org.mitre.oval:def:694 | ||||||||||||
status | accepted | ||||||||||||
submitted | 2006-08-11T12:53:40 | ||||||||||||
title | Visual Basic for Applications Vulnerability | ||||||||||||
version | 10 |
References
- http://secunia.com/advisories/21408
- http://secunia.com/advisories/21408
- http://securitytracker.com/id?1016656
- http://securitytracker.com/id?1016656
- http://www.kb.cert.org/vuls/id/159484
- http://www.kb.cert.org/vuls/id/159484
- http://www.securityfocus.com/bid/19414
- http://www.securityfocus.com/bid/19414
- http://www.us-cert.gov/cas/techalerts/TA06-220A.html
- http://www.us-cert.gov/cas/techalerts/TA06-220A.html
- http://www.vupen.com/english/advisories/2006/3214
- http://www.vupen.com/english/advisories/2006/3214
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-047
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-047
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A694
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A694