CVE-2006-2492 is a critical buffer overflow vulnerability affecting Microsoft Word (Office 2000 SP3, XP SP3, 2003 SP1/SP2) and Microsoft Works Suites through 2006. This flaw allows user-assisted attackers to execute arbitrary code through a malformed object pointer. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. This vulnerability was actively exploited as a zero-day and is listed in CISA's KEV catalog, indicating its historical and continued relevance despite a lack of public exploit intelligence tools like Metasploit or Nuclei. Community discussion and media coverage further underscore its past impact and the importance of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:* | ||
xpCPE matchmatch criteria | cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:* | ||
>= 2000, <= 2006CPE matchmatch criteria | cpe:2.3:a:microsoft:works_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.