Vulnerability Details CVE-2006-1311
The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.686
EPSS Ranking 98.5%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2006-1311
-
cpe:2.3:a:microsoft:learning_essentials:1.0
-
cpe:2.3:a:microsoft:learning_essentials:1.1
-
cpe:2.3:a:microsoft:learning_essentials:1.5
-
cpe:2.3:a:microsoft:office:-
-
cpe:2.3:a:microsoft:office:16.0.14326.21330
-
cpe:2.3:a:microsoft:office:16.0.14326.21606
-
cpe:2.3:a:microsoft:office:16.0.16026.20172
-
cpe:2.3:a:microsoft:office:16.0.16130.20156
-
cpe:2.3:a:microsoft:office:16.0.16827.20138
-
cpe:2.3:a:microsoft:office:2.70.23021003
-
cpe:2.3:a:microsoft:office:2000
-
cpe:2.3:a:microsoft:office:2001
-
cpe:2.3:a:microsoft:office:2002
-
cpe:2.3:a:microsoft:office:2003
-
cpe:2.3:a:microsoft:office:2004
-
cpe:2.3:a:microsoft:office:2007
-
cpe:2.3:a:microsoft:office:2008
-
cpe:2.3:a:microsoft:office:2010
-
cpe:2.3:a:microsoft:office:2011
-
cpe:2.3:a:microsoft:office:2013
-
cpe:2.3:a:microsoft:office:2013_rt
-
cpe:2.3:a:microsoft:office:2016
-
cpe:2.3:a:microsoft:office:2019
-
cpe:2.3:a:microsoft:office:2021
-
cpe:2.3:a:microsoft:office:3.0
-
cpe:2.3:a:microsoft:office:4.0
-
cpe:2.3:a:microsoft:office:4.3
-
cpe:2.3:a:microsoft:office:95
-
cpe:2.3:a:microsoft:office:97
-
cpe:2.3:a:microsoft:office:98
-
cpe:2.3:a:microsoft:office:xp
-
cpe:2.3:o:microsoft:windows_2000:-
-
cpe:2.3:o:microsoft:windows_2003_server:sp1
-
cpe:2.3:o:microsoft:windows_xp:-