CVE-2006-2492Active Exploitation(microsoft / office)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft office systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-06-22. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • office
  • works_suite

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
officeworks_suite

3 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-30: 2Active Exploitation · 2026-04-30: 2Patch / Workaround · 2026-04-30: 104-30
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2006-2492. Status: ✅ Confirmed exploited in the wild Date added: 2022-06-08 Required action: Apply updates per vendor instructions. Due date: 2022-06-22

    Post summary

    CVE-2006-2492 is confirmed to be exploited in the wild, with vendor-specified updates required as mitigation.

    1000021
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2006-2492-word #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The article URL indicates it discusses an active exploit for CVE‑2006-2492, but no further details are provided in the text.

    0000022
    128 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftoffice2000--
Appmicrosoftoffice2003--
Appmicrosoftoffice2003--
Appmicrosoftofficexp--
Appmicrosoftworks_suite---

Explore more