Vulnerability record · CVE-2006-2492 · published 20 May 2006
CVE-2006-2492: Microsoft Word malformed object pointer buffer overflow
Microsoft · Office
Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 SP1/SP2, and Microsoft Works Suites through 2006 contains a classic buffer overflow (CWE-120) triggered by a malformed object pointer. A user-assisted attacker can execute arbitrary code when a crafted document is opened, and the flaw was originally reported as a zero-day attack in May 2006.
Description
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8, CISA KEV listing, and a high EPSS percentile indicate active exploitation risk, though the flaw requires user interaction and affects legacy Office versions.
What it is
Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 SP1/SP2, and Microsoft Works Suites through 2006 contains a classic buffer overflow (CWE-120) triggered by a malformed object pointer. A user-assisted attacker can execute arbitrary code when a crafted document is opened, and the flaw was originally reported as a zero-day attack in May 2006.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the user who opened the document, with high confidentiality, integrity, and availability impact per the CVSS vector. This can lead to full compromise of the workstation and any credentials or data accessible to that user.
Attack surface
Reached over the network via a malicious Word document delivered by email, web, or file share, requiring the victim to open the file (UI:R) with no prior authentication (PR:N). No server-side or remote unauthenticated trigger is described; the attack depends on user interaction.
Exploitation
The record shows CISA KEV listing (added 2022-06-08) and an EPSS 30-day probability of 0.48107 (98.8th percentile), and reference tags include Exploit, indicating known exploitation. No ransomware campaign use is documented.
What to do
- Apply the Microsoft security update for MS06-027 (and the associated advisory 919637) to affected Office and Works installations.
- Upgrade or retire unsupported Office 2000/XP/2003 and Works Suites versions that no longer receive security fixes.
- Block or quarantine untrusted Office document attachments at the email and web gateway, and enforce Mark-of-the-Web/Protected View so documents open in a restricted mode.
- Run users with least privilege and disable unnecessary macros and ActiveX to limit post-exploitation impact.
Detection
- Hunt for Word processes (winword.exe) spawning child processes such as cmd.exe, powershell.exe, or wscript.exe, which is abnormal for document opening.
- Monitor for Office applications loading or writing unusual files in temp directories or making outbound network connections shortly after a document is opened.
- Alert on email attachments or downloads of Office documents from untrusted senders or newly registered domains, especially where the file is opened by Word.
- Review endpoint logs for crashes or access violations in winword.exe consistent with malformed object pointer handling.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2006-2492 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Microsoft Word Malformed Object Pointer Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-2492 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-2492), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.