PT-2009-3213 · Microsoft · Office Word+3

Nicolas Joly

·

Published

2009-06-10

·

Updated

2018-10-12

·

CVE-2009-0565

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office Word versions 2000 SP3, 2002 SP3, and 2007 SP1 and SP2 Microsoft Office for Mac versions 2004 and 2008 Open XML File Format Converter for Mac (affected versions not specified) Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats versions SP1 and SP2
Description A buffer overflow issue allows remote attackers to execute arbitrary code via a Word document with a malformed record that triggers memory corruption. This vulnerability exists in the way that Microsoft Office Word handles a specially crafted Word file, potentially allowing an attacker to take complete control of an affected system, install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Office Word versions 2000 SP3, 2002 SP3, and 2007 SP1 and SP2, update to a version that includes the fix for this issue. For Microsoft Office for Mac versions 2004 and 2008, update to a version that includes the fix for this issue. For Open XML File Format Converter for Mac, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats versions SP1 and SP2, update to a version that includes the fix for this issue.

Exploit

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0565

Affected Products

Office Compatibility Pack For Word
Office Word
Office For Mac
Open Xml File Format Converter For Mac