CVE-2008-0109
Last modified
CVE-2008-0109 is a vulnerability of currently unknown severity. Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.. EPSS estimates a 30.87% chance of exploitation in the next 30 days.
Description
Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Office | 2000 | Sp3 |
| Microsoft | Office | 2003 | — |
| Microsoft | Office | xp | Sp3 |
| Microsoft | Word | All versions | — |
References
- http://secunia.com/advisories/28901Vendor Advisory
- http://www.kb.cert.org/vuls/id/692417US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA08-043C.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/0511/referencesVendor Advisory
- http://secunia.com/advisories/28901Vendor Advisory
- http://www.kb.cert.org/vuls/id/692417US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA08-043C.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/0511/referencesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0109?
How severe is CVE-2008-0109?
How do I fix CVE-2008-0109?
Are you affected by CVE-2008-0109?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
