PT-2008-1764 · Microsoft · Office Xp+4
Rubén Santamarta
·
Published
2008-02-12
·
Updated
2018-10-15
·
CVE-2008-0109
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Word versions in Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003
Description
A remote code execution issue exists in the way that Word handles specially crafted Word files. This could allow remote code execution if a user opens a specially crafted Word file that includes a malformed value. An attacker who successfully exploits this issue could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights. The issue is triggered by crafted fields within the File Information Block (FIB) of a Word file, which causes length calculation errors and memory corruption.
Recommendations
For Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Word
Office 2000
Office 2003
Office Word Viewer 2003
Office Xp