CVE-2006-2389

Microsoft Office - Code Injection

Title source: rule

Description

Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · pythonremotewindows
https://www.exploit-db.com/exploits/28198

Scores

EPSS 0.7423
EPSS Percentile 98.9%

Details

CWE
CWE-94
Status published
Products (3)
microsoft/office 2000 sp3
microsoft/office 2003 sp1 (2 CPE variants)
microsoft/office xp sp3
Published Jul 11, 2006
Tracked Since Feb 18, 2026