CVE-2004-0848: Buffer Overflow
Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0848?
CVE-2004-0848 has been rated as high severity due to the potential for remote code execution.
How do I fix CVE-2004-0848?
To fix CVE-2004-0848, you should apply the latest security updates provided by Microsoft for affected software.
Which versions of Microsoft software are affected by CVE-2004-0848?
CVE-2004-0848 affects Microsoft Office XP, Microsoft Word, Microsoft Visio, Microsoft PowerPoint, and Microsoft Project versions 2002.
What are the attack vectors for CVE-2004-0848?
CVE-2004-0848 can be exploited via crafted .doc or .rtf files containing long inputs terminated with a null byte or carriage return.
Can CVE-2004-0848 be exploited remotely?
Yes, CVE-2004-0848 allows remote attackers to execute arbitrary code through maliciously crafted files.