PT-2008-5339 · Microsoft · Office Word+1

Ricardo Narvaja

·

Published

2008-12-10

·

Updated

2018-10-30

·

CVE-2008-4024

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office Word versions 2000 SP3 and 2002 SP3 Microsoft Office 2004 for Mac
Description A remote code execution issue exists in the way Word handles specially crafted Word files, potentially allowing arbitrary code execution if a user opens a malformed file. This could be triggered by a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), bypassing an initialization step and causing an "arbitrary free." Users with fewer user rights on the system may be less impacted than those operating with administrative rights.
Recommendations For Microsoft Office Word 2000 SP3, update to a version that is not affected by this issue. For Microsoft Office Word 2002 SP3, apply the necessary patch or update to a secure version. For Microsoft Office 2004 for Mac, consider disabling the handling of specially crafted Word files until a patch is available.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4024

Affected Products

Office
Office Word