CVE Database
/

CVE-2006-1540

Back to search

CVE-2006-1540

Published: Mar 30, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt. NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode "Sheet Name" string.

VendorProductVersions

n/a

n/a

affected
n/a

References

21012
third-party-advisory
x_refsource_SECUNIA
ADV-2006-2756
vdb-entry
x_refsource_VUPEN
MS06-038
vendor-advisory
x_refsource_MS
VU#609868
third-party-advisory
x_refsource_CERT-VN
office-string-parse-bo(27607)
vdb-entry
x_refsource_XF
office-property-string-bo(27609)
vdb-entry
x_refsource_XF
17252
vdb-entry
x_refsource_BID
18889
vdb-entry
x_refsource_BID
TA06-192A
third-party-advisory
x_refsource_CERT
27150
vdb-entry
x_refsource_OSVDB
oval:org.mitre.oval:def:639
vdb-entry
signature
x_refsource_OVAL
1615
exploit
x_refsource_EXPLOIT-DB
1015855
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now