Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X...
Vulnerability Description
Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3650
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/20383
- http://www.securityfocus.com/archive/1/448151/100/0/threaded
- http://www.osvdb.org/29428
- http://www.securityfocus.com/archive/1/449179/100/0/threaded
- http://www.vupen.com/english/advisories/2006/3981
- http://www.zerodayinitiative.com/advisories/ZDI-06-034.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-062
- http://securitytracker.com/id?1017034
- http://www.securityfocus.com/archive/1/449179/100/0/threaded
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A222
- http://www.kb.cert.org/vuls/id/534276
- http://secunia.com/advisories/22339
More from microsoft
View All →Affected Vendor
microsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.