CVE-2006-5994

EXPLOITED

Microsoft Word 2000-2006 Remote Code Execution via Malformed String

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2006-5994 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.

References (17)

Core 17
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30738
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-044A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A238
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4866
Various Sources x_refsource_misc
http://blogs.securiteam.com/?p=759
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23232
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/30824
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/453735/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/453906/100/0/threaded
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/167928
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017339
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21451
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/454061/100/0/threaded

Scores

EPSS 0.3130
EPSS Percentile 98.1%

Details

VulnCheck KEV 2007-02-13
Status published
Products (11)
microsoft/office 2000 sp3
microsoft/office 2003 sp2
microsoft/office 2004
microsoft/office xp sp3
microsoft/word 2000
microsoft/word 2002
microsoft/word 2003
microsoft/word_viewer 2003
microsoft/works 2004
microsoft/works 2005
... and 1 more
Published Dec 06, 2006
Tracked Since Feb 18, 2026