CVE-2007-1202
Last modified
CVE-2007-1202 is a vulnerability of currently unknown severity. Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability.". EPSS estimates a 29.48% chance of exploitation in the next 30 days.
Description
Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Word | 2000 | Sp3 |
| Microsoft | Word | 2002 | Sp3 |
| Microsoft | Word | 2003 | Sp2 |
| Microsoft | Word | 2004 | — |
| Microsoft | Word Viewer | 2003 | — |
| Microsoft | Works | 2004 | — |
| Microsoft | Works | 2005 | — |
| Microsoft | Works | 2006 | — |
References
- http://www.kb.cert.org/vuls/id/555489US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-128A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/1709Vendor Advisory
- http://www.kb.cert.org/vuls/id/555489US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA07-128A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/1709Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1202?
How severe is CVE-2007-1202?
How do I fix CVE-2007-1202?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1195Multiple buffer overflows in XM Easy Personal FTP Server 5.3…
- CVE-2007-1196Unspecified vulnerability in Citrix Presentation Server Clie…
- CVE-2007-1197Multiple unspecified vulnerabilities in Epiware before 4.7.5…
- CVE-2007-1198Cross-site scripting (XSS) vulnerability in TaskFreak! befor…
- CVE-2007-1199Adobe Reader and Acrobat Trial allow remote attackers to rea…
- CVE-2007-1201Unspecified vulnerability in certain COM objects in Microsof…
- CVE-2007-1203Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 …
- CVE-2007-1204Stack-based buffer overflow in the Universal Plug and Play (…
- CVE-2007-1205Unspecified vulnerability in Microsoft Agent (msagent\agents…
- CVE-2007-1206The Virtual DOS Machine (VDM) in the Windows Kernel in Micro…
- CVE-2007-1207Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-1208Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2007-1202?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
