CVE-2006-1311

Description

The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
70.645

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows 2000 (KB918118)Windows
Security Update for Windows XP (KB918118)Windows
Security Update for Windows Server 2003 (KB918118) x86 based systemsWindows
Security Update for Windows Server 2003 (KB918118) x86 based systems for SP1Windows
Security Update for Office 2000 (KB920906)Windows
Security Update for Office XP (KB920816)Windows
Security Update for Office 2003 (KB920813)Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234