CVE-2006-2389
Microsoft Office - Code Injection
Title source: ruleDescription
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by anonymous · pythonremotewindows
https://www.exploit-db.com/exploits/28198
References (10)
Scores
EPSS
0.7423
EPSS Percentile
98.9%
Details
CWE
CWE-94
Status
published
Products (3)
microsoft/office
2000 sp3
microsoft/office
2003 sp1 (2 CPE variants)
microsoft/office
xp sp3
Published
Jul 11, 2006
Tracked Since
Feb 18, 2026