← Vulnerability feed

Vulnerability record · CVE-2006-2492 · published 20 May 2006

CVE-2006-2492: Microsoft Word malformed object pointer buffer overflow

Microsoft · Office

Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 SP1/SP2, and Microsoft Works Suites through 2006 contains a classic buffer overflow (CWE-120) triggered by a malformed object pointer. A user-assisted attacker can execute arbitrary code when a crafted document is opened, and the flaw was originally reported as a zero-day attack in May 2006.

8.8 CVSS 3.1 High CISA KEV since 8 Jun 2022 EPSS 48% · top 1.2% CWE-120 · Classic buffer overflow
8.8CVSS 3.1 base score, v2 7.6
48%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
35References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8, CISA KEV listing, and a high EPSS percentile indicate active exploitation risk, though the flaw requires user interaction and affects legacy Office versions.

What it is

Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 SP1/SP2, and Microsoft Works Suites through 2006 contains a classic buffer overflow (CWE-120) triggered by a malformed object pointer. A user-assisted attacker can execute arbitrary code when a crafted document is opened, and the flaw was originally reported as a zero-day attack in May 2006.

Impact

Successful exploitation gives the attacker arbitrary code execution in the context of the user who opened the document, with high confidentiality, integrity, and availability impact per the CVSS vector. This can lead to full compromise of the workstation and any credentials or data accessible to that user.

Attack surface

Reached over the network via a malicious Word document delivered by email, web, or file share, requiring the victim to open the file (UI:R) with no prior authentication (PR:N). No server-side or remote unauthenticated trigger is described; the attack depends on user interaction.

Exploitation

The record shows CISA KEV listing (added 2022-06-08) and an EPSS 30-day probability of 0.48107 (98.8th percentile), and reference tags include Exploit, indicating known exploitation. No ransomware campaign use is documented.

What to do

  • Apply the Microsoft security update for MS06-027 (and the associated advisory 919637) to affected Office and Works installations.
  • Upgrade or retire unsupported Office 2000/XP/2003 and Works Suites versions that no longer receive security fixes.
  • Block or quarantine untrusted Office document attachments at the email and web gateway, and enforce Mark-of-the-Web/Protected View so documents open in a restricted mode.
  • Run users with least privilege and disable unnecessary macros and ActiveX to limit post-exploitation impact.

Detection

  • Hunt for Word processes (winword.exe) spawning child processes such as cmd.exe, powershell.exe, or wscript.exe, which is abnormal for document opening.
  • Monitor for Office applications loading or writing unusual files in temp directories or making outbound network connections shortly after a document is opened.
  • Alert on email attachments or downloads of Office documents from untrusted senders or newly registered domains, especially where the file is opened by Word.
  • Review endpoint logs for crashes or access violations in winword.exe consistent with malformed object pointer handling.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2006-2492 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Microsoft Word Malformed Object Pointer Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx Broken Link
http://isc.sans.org/diary.php?storyid=1345 Exploit
http://isc.sans.org/diary.php?storyid=1346 Exploit
http://secunia.com/advisories/20153 Broken LinkPatchVendor Advisory
http://securitytracker.com/id?1016130 Broken LinkThird Party AdvisoryVDB Entry
http://www.kb.cert.org/vuls/id/446012 Third Party AdvisoryUS Government Resource
http://www.microsoft.com/technet/security/advisory/919637.mspx Broken LinkPatchVendor Advisory
http://www.osvdb.org/25635 Broken Link
http://www.securityfocus.com/bid/18037 Broken LinkPatchThird Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA06-139A.html Broken LinkThird Party AdvisoryUS Government Resource
http://www.us-cert.gov/cas/techalerts/TA06-164A.html Broken LinkThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2006/1872 Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/26556 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068 Broken Link
http://blogs.technet.com/msrc/archive/2006/05/19/429353.aspx Broken Link
http://isc.sans.org/diary.php?storyid=1345 Exploit
http://isc.sans.org/diary.php?storyid=1346 Exploit
http://secunia.com/advisories/20153 Broken LinkPatchVendor Advisory
http://securitytracker.com/id?1016130 Broken LinkThird Party AdvisoryVDB Entry
http://www.kb.cert.org/vuls/id/446012 Third Party AdvisoryUS Government Resource
http://www.microsoft.com/technet/security/advisory/919637.mspx Broken LinkPatchVendor Advisory
http://www.osvdb.org/25635 Broken Link
http://www.securityfocus.com/bid/18037 Broken LinkPatchThird Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA06-139A.html Broken LinkThird Party AdvisoryUS Government Resource
http://www.us-cert.gov/cas/techalerts/TA06-164A.html Broken LinkThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2006/1872 Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-027 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/26556 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1418 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1738 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2068 Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2006-2492 US Government Resource

Track CVE-2006-2492 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2006-2492), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.