// For flags

CVE-2006-3649

 

Severity Score

5.1
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.

Desbordamiento de búfer en Microsoft Visual Basic para Aplicaciones (VBA) SDK 6.0 hasta 6.4, como se usa en Microsoft Office 2000 SP3, Office XPSP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, y Works Suite 2004 hasta 2006, permite a atacantes remotos con intervención del usuario ejecutar código de su elección mediante propiedades de documento no especificadas que no son verificadas cuando VBA es invocado para abrir documentos.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-07-17 CVE Reserved
  • 2006-08-09 CVE Published
  • 2024-06-29 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Visual Basic
Search vendor "Microsoft" for product "Visual Basic"
6.2
Search vendor "Microsoft" for product "Visual Basic" and version "6.2"
-
Affected
Microsoft
Search vendor "Microsoft"
Visual Basic
Search vendor "Microsoft" for product "Visual Basic"
6.2
Search vendor "Microsoft" for product "Visual Basic" and version "6.2"
sdk
Affected
Microsoft
Search vendor "Microsoft"
Visual Basic
Search vendor "Microsoft" for product "Visual Basic"
6.3
Search vendor "Microsoft" for product "Visual Basic" and version "6.3"
sdk
Affected
Microsoft
Search vendor "Microsoft"
Visual Basic
Search vendor "Microsoft" for product "Visual Basic"
6.4
Search vendor "Microsoft" for product "Visual Basic" and version "6.4"
sdk
Affected