CVE-2006-3493
Description
Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer overflow in the LsCreateLine function (mso_203) of mso.dll and mso9.dll in Microsoft Office 2003, 2002, and 2000 causes a denial of service via a crafted DOC file.
Vulnerability
The vulnerability is a buffer overflow in the LsCreateLine function (entry point mso_203) of mso.dll (or mso9.dll in older versions). This function fails to properly validate input when parsing a specially crafted .DOC or other Office file type, leading to an invalid memory access. The issue affects Microsoft Office 2000, Office 2002 (XP), and Office 2003, specifically the versions of mso.dll and mso9.dll shipped with Word and possibly other Office products that use these libraries. The original report indicated that a buffer overflow could occur when the software processes a malformed file, as demonstrated by a proof-of-concept code that generates a crashing .doc file [1].
Exploitation
An attacker must convince a user to open a crafted Office file (e.g., .doc) with a vulnerable version of Microsoft Word or another affected Office application. The attacker does not need any special network position or authentication beyond delivering the malformed file to the target (e.g., via email attachment or web download). User interaction is required (opening the file) and no other conditions are needed to trigger the overflow. According to the researcher's analysis, the LsCreateLine function is called during file parsing and, when processing overly large or malformed data, it overwrites buffers within the heap, resulting in an access violation [1].
Impact
Successfully exploiting the vulnerability causes Microsoft Word (or the host application) to crash, resulting in a denial of service. While the initial disclosure claimed code execution might be possible via a 4-byte arbitrary memory overwrite, Microsoft stated on July 10, 2006 that code execution is not achievable, and the original researcher later agreed with this assessment [1][2]. Therefore, the confirmed impact is limited to a denial of service: the application terminates abnormally when the malformed file is loaded. No privileged access or data disclosure is achieved [3].
Mitigation
Microsoft acknowledged the issue in a July 10, 2006 blog post and stated that the vulnerability is not remotely exploitable [3]. No official patch was released specifically for this CVE at that time. Users are advised to exercise caution when opening untrusted Office documents. As of the publication date (2006-07-10), no fix was available, and the vulnerability was not listed on the Known Exploited Vulnerabilities (KEV) catalog. Users should apply the latest Office service packs and security updates to reduce overall risk [1][2][3].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
13cpe:2.3:a:microsoft:office:2000:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:microsoft:office:2000:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2000:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2000:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2003:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:xp:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:xp:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:xp:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.securityfocus.com/bid/18905nvdExploit
- blogs.technet.com/msrc/archive/2006/07/10/441006.aspxnvd
- lists.grok.org.uk/pipermail/full-disclosure/2006-July/047732.htmlnvd
- marc.infonvd
- marc.infonvd
- securitytracker.com/idnvd
- www.securityfocus.com/archive/1/439649/100/0/threadednvd
- www.securityfocus.com/archive/1/439878/100/0/threadednvd
- www.vupen.com/english/advisories/2006/2720nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/27617nvd
News mentions
0No linked articles in our index yet.