MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt
Published Mar 30, 2006
9.3
HIGHCVSS 2.0
EPSS 28.63%
Description
MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt. NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode "Sheet Name" string.
Affected products
No data.
- n/a
- 2000
- 2000
- 2000
- 2000
- 2000
- 2000
- 2003
- 2003
- 2003
- 2004
- v.x
- xp
- xp
- xp
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 28.63% (0.28632) | 98.09th | v5 (v2026.06.15) |
| Jul 28, 2026 | 28.63% (0.28632) | 97.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 43.66% (0.43664) | 98.57th | v5 (v2026.06.15) |
| Apr 28, 2026 | 70.34% (0.70342) | 98.70th | v4 (v2025.03.14) |
| Jul 29, 2025 | 74.66% (0.74659) | 98.79th | v4 (v2025.03.14) |
| Mar 30, 2025 | 69.80% (0.69796) | 98.56th | v4 (v2025.03.14) |
| Mar 29, 2025 | 71.60% (0.71604) | 98.30th | v4 (v2025.03.14) |
| Mar 19, 2025 | 69.80% (0.69796) | 98.53th | v4 (v2025.03.14) |
| Mar 17, 2025 | 67.21% (0.67206) | 98.43th | v4 (v2025.03.14) |
| Mar 6, 2025 | 51.68% (0.51679) | 97.75th | v3 (v2023.03.01) |
| Dec 17, 2024 | 42.97% (0.42973) | 97.39th | v3 (v2023.03.01) |
| Jul 19, 2024 | 58.06% (0.58065) | 97.77th | v3 (v2023.03.01) |
| Oct 10, 2023 | 45.52% (0.45519) | 96.98th | v3 (v2023.03.01) |
| Jul 4, 2023 | 48.43% (0.48429) | 96.97th | v3 (v2023.03.01) |
| Apr 18, 2023 | 52.42% (0.52420) | 97.03th | v3 (v2023.03.01) |
| Mar 7, 2023 | 47.49% (0.47487) | 96.84th | v3 (v2023.03.01) |
| Mar 6, 2023 | 39.18% (0.39185) | 98.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 39.18% (0.39185) | 97.32th | v2 (v2022.01.01) |
References (14)
- http://secunia.com/advisories/21012 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://securitytracker.com/id?1015855 vdb-entryx_refsource_SECTRACKExploitThird Party AdvisoryVDB Entry
- http://www.kb.cert.org/vuls/id/609868 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.osvdb.org/27150 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/archive/1/439697/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17252 vdb-entryx_refsource_BIDExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/18889 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA06-192A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2006/2756 vdb-entryx_refsource_VUPENVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-038 vendor-advisoryx_refsource_MS
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27607 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27609 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A639 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.exploit-db.com/exploits/1615 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/21012 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://securitytracker.com/id?1015855 | vdb-entryx_refsource_SECTRACKExploitThird Party AdvisoryVDB Entry | |
| http://www.kb.cert.org/vuls/id/609868 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| http://www.osvdb.org/27150 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://www.securityfocus.com/archive/1/439697/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/17252 | vdb-entryx_refsource_BIDExploitThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/18889 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.us-cert.gov/cas/techalerts/TA06-192A.html | third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2006/2756 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-038 | vendor-advisoryx_refsource_MS | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/27607 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/27609 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A639 | vdb-entrysignaturex_refsource_OVALThird Party Advisory | |
| https://www.exploit-db.com/exploits/1615 | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.