PT-2007-2627 · Microsoft · Office 2000+4

Published

2007-05-08

·

Updated

2018-10-16

·

CVE-2007-1202

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Word versions in Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006
Description The issue is related to the improper parsing of certain rich text "property strings of certain control words" in Microsoft Word, which can lead to heap corruption and allow remote attackers to execute arbitrary code. This can be triggered by a specially crafted Word file, potentially included as an email attachment or hosted on a malicious website.
Recommendations For Microsoft Word in Office 2000 SP3, update to a version that includes the fix for this issue. For Microsoft Word in Office XP SP3, update to a version that includes the fix for this issue. For Microsoft Word in Office 2003 SP2, update to a version that includes the fix for this issue. For Microsoft Word 2004 for Mac, update to a version that includes the fix for this issue. For Microsoft Word in Works Suite 2004, 2005, and 2006, update to a version that includes the fix for this issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-1202

Affected Products

Office Word
Office 2000
Office 2003
Office Xp
Works Suite