← Vulnerability feed

Vulnerability record · CVE-2006-3590 · published 14 July 2006

CVE-2006-3590: Microsoft powerpoint vulnerability

Microsoft · Powerpoint

mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.

5.1 CVSS 2.0 Medium EPSS 14% · top 3.5%
5.1CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.securiteam.com/?p=508
http://isc.sans.org/diary.php?storyid=1484
http://secunia.com/advisories/21040 Vendor Advisory
http://securityresponse.symantec.com/avcenter/venc/data/trojan.ppdropper.b.html
http://securitytracker.com/id?1016496
http://www.kb.cert.org/vuls/id/936945 US Government Resource
http://www.osvdb.org/27324
http://www.securityfocus.com/archive/1/440137/100/0/threaded
http://www.securityfocus.com/archive/1/440255/100/0/threaded
http://www.securityfocus.com/archive/1/440532/100/0/threaded
http://www.securityfocus.com/bid/18957
http://www.us-cert.gov/cas/techalerts/TA06-220A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2795 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-048
https://exchange.xforce.ibmcloud.com/vulnerabilities/27740
https://exchange.xforce.ibmcloud.com/vulnerabilities/27781
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A399
http://blogs.securiteam.com/?p=508
http://isc.sans.org/diary.php?storyid=1484
http://secunia.com/advisories/21040 Vendor Advisory
http://securityresponse.symantec.com/avcenter/venc/data/trojan.ppdropper.b.html
http://securitytracker.com/id?1016496
http://www.kb.cert.org/vuls/id/936945 US Government Resource
http://www.osvdb.org/27324
http://www.securityfocus.com/archive/1/440137/100/0/threaded
http://www.securityfocus.com/archive/1/440255/100/0/threaded
http://www.securityfocus.com/archive/1/440532/100/0/threaded
http://www.securityfocus.com/bid/18957
http://www.us-cert.gov/cas/techalerts/TA06-220A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2795 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-048
https://exchange.xforce.ibmcloud.com/vulnerabilities/27740
https://exchange.xforce.ibmcloud.com/vulnerabilities/27781
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A399

Track CVE-2006-3590 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2009-0556Microsoft PowerPoint memory corruption via malformed OutlineTextRefAtomMicrosoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac mishandle an OutlineTextRefAtom with an invalid index value,…KEVEPSS 67%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed7.8CVE-2010-2572Microsoft PowerPoint buffer overflow via crafted PowerPoint 95 fileMicrosoft PowerPoint 2002 SP3 and 2003 SP3 contain a buffer overflow when parsing a crafted PowerPoint 95 document. Opening the malicious file can co…KEVEPSS 59%analysed9.3CVE-2015-2503Microsoft access permissions and access controls vulnerabilityMicrosoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007…EPSS 17%9.3CVE-2015-1682Microsoft excel memory buffer overflow vulnerabilityMicrosoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, O…EPSS 19%9.3CVE-2015-0097Microsoft excel vulnerabilityMicrosoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execut…EPSS 41%9.3CVE-2015-0085Microsoft excel vulnerabilityUse-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, Power…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2006-3590), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.