PT-2008-5339 · Microsoft · Office Word+1
Ricardo Narvaja
·
Published
2008-12-10
·
Updated
2018-10-30
·
CVE-2008-4024
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office Word versions 2000 SP3 and 2002 SP3
Microsoft Office 2004 for Mac
Description
A remote code execution issue exists in the way Word handles specially crafted Word files, potentially allowing arbitrary code execution if a user opens a malformed file. This could be triggered by a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), bypassing an initialization step and causing an "arbitrary free." Users with fewer user rights on the system may be less impacted than those operating with administrative rights.
Recommendations
For Microsoft Office Word 2000 SP3, update to a version that is not affected by this issue.
For Microsoft Office Word 2002 SP3, apply the necessary patch or update to a secure version.
For Microsoft Office 2004 for Mac, consider disabling the handling of specially crafted Word files until a patch is available.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office
Office Word