CVE-2007-0209
Last modified
CVE-2007-0209 is a vulnerability of currently unknown severity. Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.. EPSS estimates a 29.09% chance of exploitation in the next 30 days.
Description
Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Office | 2000 | Sp3 |
| Microsoft | Office | 2003 | Sp2 |
| Microsoft | Office | 2004 | — |
| Microsoft | Office | xp | Sp3 |
| Microsoft | Works | 2004 | — |
| Microsoft | Works | 2005 | — |
| Microsoft | Works | 2006 | — |
References
- http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/0583Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/0583Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0209?
How severe is CVE-2007-0209?
How do I fix CVE-2007-0209?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0203Multiple unspecified vulnerabilities in phpMyAdmin before 2.…
- CVE-2007-0204Multiple cross-site scripting (XSS) vulnerabilities in phpMy…
- CVE-2007-0205Directory traversal vulnerability in admin/skins.php for @le…
- CVE-2007-0206Unspecified vulnerability in HP OpenView Network Node Manage…
- CVE-2007-0207Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-0208Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, …
- CVE-2007-0210The Window Image Acquisition (WIA) Service in Microsoft Wind…
- CVE-2007-0211The hardware detection functionality in the Windows Shell in…
- CVE-2007-0212Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-0213Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 20…
- CVE-2007-0214The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Wind…
- CVE-2007-0215Stack-based buffer overflow in Microsoft Excel 2000 SP3, 200…
Are you affected by CVE-2007-0209?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
