PT-2007-1692 · Microsoft · Works Suite+5

Published

2007-02-13

·

Updated

2018-10-12

·

CVE-2007-0209

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Word versions in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac
Description A remote code execution issue exists in Microsoft Word, where an attacker could exploit this by constructing a specially crafted Word file with a malformed drawing object. This could lead to memory corruption and allow remote code execution when Word parses the file. Such a file might be included as an e-mail attachment or hosted on a malicious Web site.
Recommendations For Microsoft Word in Office 2000 SP3, update to a version that includes the fix for this issue. For Microsoft Word in XP SP3, update to a version that includes the fix for this issue. For Microsoft Word in Office 2003 SP2, update to a version that includes the fix for this issue. For Microsoft Word in Works Suite 2004 to 2006, update to a version that includes the fix for this issue. For Microsoft Word in Office 2004 for Mac, update to a version that includes the fix for this issue. As a temporary workaround, consider avoiding the use of Word files from untrusted sources until a patch is available.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0209

Affected Products

Office Word
Office 2000
Office 2003
Office 2004 For Mac
Office Xp
Works Suite