Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-2492

85
FAUCET Score

CVE-2006-2492 is a critical buffer overflow vulnerability affecting Microsoft Word (Office 2000 SP3, XP SP3, 2003 SP1/SP2) and Microsoft Works Suites through 2006. This flaw allows user-assisted attackers to execute arbitrary code through a malformed object pointer. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. This vulnerability was actively exploited as a zero-day and is listed in CISA's KEV catalog, indicating its historical and continued relevance despite a lack of public exploit intelligence tools like Metasploit or Nuclei. Community discussion and media coverage further underscore its past impact and the importance of patching.

Impacted Technologies

VendorProductVersion(s)CPE
2000CPE matchmatch criteria
cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
2003CPE matchmatch criteria
cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*
2003CPE matchmatch criteria
cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*
xpCPE matchmatch criteria
cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
>= 2000, <= 2006CPE matchmatch criteria
cpe:2.3:a:microsoft:works_suite:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
48.39%
Probability of exploitation in next 30 days
EPSS Percentile
98.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Jun 8, 2022
This CVE's current EPSS score of 0.4839 is in the 99th percentile among its peer group of 14,852 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

microsoftpatch availablevia nvd_reference
View patch

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
blogs.technet.com / msrc/archive/2006/05/19/429353.aspx
Broken Link
isc.sans.org / diary.php
Exploit
isc.sans.org / diary.php
Exploit
docs.microsoft.com / en-us/security-updates/securitybulletins/2006/ms06-027
PatchVendor Advisory
secunia.com / advisories/20153
Broken LinkPatchVendor Advisory
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/26556
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068
Broken Link
kb.cert.org / vuls/id/446012
Third Party AdvisoryUS Government Resource
microsoft.com / technet/security/advisory/919637.mspx
Broken LinkPatchVendor Advisory
osvdb.org / 25635
Broken Link
securityfocus.com / bid/18037
Broken LinkPatchThird Party AdvisoryVDB Entry
us-cert.gov / cas/techalerts/TA06-139A.html
Broken LinkThird Party AdvisoryUS Government Resource
us-cert.gov / cas/techalerts/TA06-164A.html
Broken LinkThird Party AdvisoryUS Government Resource
vupen.com / english/advisories/2006/1872
Broken Link