PT-2007-2627 · Microsoft · Office 2000+4
Published
2007-05-08
·
Updated
2018-10-16
·
CVE-2007-1202
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Word versions in Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006
Description
The issue is related to the improper parsing of certain rich text "property strings of certain control words" in Microsoft Word, which can lead to heap corruption and allow remote attackers to execute arbitrary code. This can be triggered by a specially crafted Word file, potentially included as an email attachment or hosted on a malicious website.
Recommendations
For Microsoft Word in Office 2000 SP3, update to a version that includes the fix for this issue.
For Microsoft Word in Office XP SP3, update to a version that includes the fix for this issue.
For Microsoft Word in Office 2003 SP2, update to a version that includes the fix for this issue.
For Microsoft Word 2004 for Mac, update to a version that includes the fix for this issue.
For Microsoft Word in Works Suite 2004, 2005, and 2006, update to a version that includes the fix for this issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Word
Office 2000
Office 2003
Office Xp
Works Suite