Description: A vulnerability has been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a memory corruption error when handling Word documents using a malformed object pointer.
Successful exploitation allows execution of arbitrary code.
NOTE: This vulnerability is being actively exploited.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.
Provided and/or discovered by: This vulnerability has been discovered in the wild as a "Zero-day" while investigating a system compromise.
The vendor also credits Shih-hao Weng.
Changelog: 2006-05-23: Added CVE reference. Updated advisory.
2006-06-13: Added additional information from the vendor. Updated "Description" and "Solution" sections. Added link to vendor advisory.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.