LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2006-2492: Microsoft Word Malformed Object Pointer Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2006-2492 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.

CVE-2006-2492 is a malformed object pointer vulnerability in Microsoft Word and Microsoft Works Suites that can allow an attacker to execute code. It matters because Word documents are routinely opened from email, shares, and downloads; a successful exploit can give the attacker control in the context of the user who opens the file.

Public detail is limited to the CISA summary and the assigned weakness. Confirm exact product editions, fixed builds, and deployment guidance against the vendor advisory before acting.

How it works

The weakness is classified as CWE-120 (buffer copy without checking size of input). In this class of flaw, the application mishandles a malformed object or related structure inside a document so that memory is corrupted. An attacker who can supply a crafted Word document can abuse that corruption to run arbitrary code when the document is opened or previewed.

No exploit mechanics, payload formats, or reliability details are provided in the given facts. Treat any document from an untrusted source as a potential delivery vehicle for this class of issue, and rely on the vendor advisory for precise technical description.

Am I affected? How to find it in your systems

Microsoft Word and Microsoft Works Suites are the affected products named in the facts. These typically run on end-user Windows workstations, terminal servers, and any system where Office or Works is installed for document editing or viewing.

How to remediate

Patch first. Apply the updates provided by the vendor for Microsoft Word and Microsoft Works Suites exactly as directed in the vendor advisory and in line with the CISA required action to apply updates per vendor instructions.

If you can't patch immediately

Use compensating controls until the vendor update can be applied everywhere.

If your data may have been exposed

Actively exploited document vulnerabilities can lead to workstation compromise and follow-on data theft or ransomware, although ransomware use is not documented for this CVE in the given facts. If you suspect successful exploitation, isolate the host, preserve memory and disk evidence, rotate credentials accessible from that host, and begin incident response. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Word
WeaknessCWE-120
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities