PT-2004-1670 · Microsoft · Word For Windows 6.0 Converter

Greg Jones

·

Published

2004-12-15

·

Updated

2019-04-30

·

CVE-2004-0571

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Word for Windows 6.0 Converter
Description The issue arises from the improper validation of certain data lengths, allowing remote attackers to execute arbitrary code. This can be achieved by sending a malicious .wri, .rtf, or .doc file via email or hosting it on a malicious website.
Recommendations For Microsoft Word for Windows 6.0 Converter, update to a version that properly validates data lengths to prevent arbitrary code execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0571

Affected Products

Word For Windows 6.0 Converter