CVE-2006-3493

Microsoft Office <2003 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-3493. PoCs published by naveed afzal.

AI-analyzed exploit summary This exploit generates a malformed .DOC file that triggers an unchecked boundary condition in Microsoft Office's mso.dll, leading to an access violation. The PoC demonstrates the vulnerability but does not include a payload for arbitrary code execution.

Description

Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.

Exploits (1)

exploitdb WORKING POC VERIFIED
by naveed afzal · cdoswindows
https://www.exploit-db.com/exploits/2001

This exploit generates a malformed .DOC file that triggers an unchecked boundary condition in Microsoft Office's mso.dll, leading to an access violation. The PoC demonstrates the vulnerability but does not include a payload for arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (Word 2000, 2002, 2003)
No auth needed
Prerequisites: Victim must open the malformed .DOC file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18905
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/439649/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016453
Mailing List mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047732.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2720
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=115231380526820&w=2
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=115261598510657&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27617
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/439878/100/0/threaded

Scores

EPSS 0.4041
EPSS Percentile 98.5%

Details

Status published
Products (3)
microsoft/office 2000 (4 CPE variants)
microsoft/office 2003 (4 CPE variants)
microsoft/office xp (4 CPE variants)
Published Jul 10, 2006
Tracked Since Feb 18, 2026