Lucene search

K
cveMicrosoftCVE-2006-1311
HistoryFeb 13, 2007 - 8:28 p.m.

CVE-2006-1311

2007-02-1320:28:00
microsoft
web.nvd.nist.gov
30
20
cve-2006-1311
richedit component
remote code execution
ole object
memory corruption
microsoft windows
office
learning essentials
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.888

Percentile

98.7%

The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.

Affected configurations

Nvd
Node
microsoftlearning_essentialsMatch1.0
OR
microsoftlearning_essentialsMatch1.1
OR
microsoftlearning_essentialsMatch1.5
OR
microsoftoffice
OR
microsoftofficeMatch2000sp3
OR
microsoftofficeMatch2003sp2
OR
microsoftofficeMatchxpsp3
Node
microsoftwindows_2000sp4fr
OR
microsoftwindows_2003_serverMatchsp1
OR
microsoftwindows_xpsp2tablet_pc
VendorProductVersionCPE
microsoftlearning_essentials1.0cpe:2.3:a:microsoft:learning_essentials:1.0:*:*:*:*:*:*:*
microsoftlearning_essentials1.1cpe:2.3:a:microsoft:learning_essentials:1.1:*:*:*:*:*:*:*
microsoftlearning_essentials1.5cpe:2.3:a:microsoft:learning_essentials:1.5:*:*:*:*:*:*:*
microsoftoffice*cpe:2.3:a:microsoft:office:*:*:*:*:*:*:*:*
microsoftoffice2000cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
microsoftoffice2003cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*
microsoftofficexpcpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
microsoftwindows_2000*cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*
microsoftwindows_2003_serversp1cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*

Social References

More

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.888

Percentile

98.7%