PT-2004-1670 · Microsoft · Word For Windows 6.0 Converter
Greg Jones
·
Published
2004-12-15
·
Updated
2019-04-30
·
CVE-2004-0571
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Word for Windows 6.0 Converter
Description
The issue arises from the improper validation of certain data lengths, allowing remote attackers to execute arbitrary code. This can be achieved by sending a malicious .wri, .rtf, or .doc file via email or hosting it on a malicious website.
Recommendations
For Microsoft Word for Windows 6.0 Converter, update to a version that properly validates data lengths to prevent arbitrary code execution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Word For Windows 6.0 Converter