PT-2008-1758 · Microsoft · Office
Publicado
2008-02-12
·
Atualizado
2018-10-12
·
CVE-2008-0103
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office versions 2000 SP3, XP SP3, 2003 SP2, and 2004 for Mac
Description
The issue allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a memory handling error. If a user opens a specially crafted Microsoft Office document with a malformed object inserted into the document, it could allow remote code execution. An attacker who successfully exploited this issue could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Microsoft Office 2000 SP3, update to a version that fixes the memory handling error to prevent remote code execution.
For Microsoft Office XP SP3, update to a version that fixes the memory handling error to prevent remote code execution.
For Microsoft Office 2003 SP2, update to a version that fixes the memory handling error to prevent remote code execution.
For Microsoft Office 2004 for Mac, update to a version that fixes the memory handling error to prevent remote code execution.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Office