First published: Wed Oct 20 2004(Updated: )
Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Word | =2002-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0963 has a high severity due to its potential to cause denial of service and execute arbitrary code.
The recommended fix for CVE-2004-0963 is to update Microsoft Word to the latest version or apply any available security patches.
CVE-2004-0963 primarily affects Microsoft Word 2002 (10.6612.6714) SP3 and potentially other versions.
CVE-2004-0963 is associated with a buffer overflow attack that can be triggered by specially crafted .doc files.
At the time of its discovery, CVE-2004-0963 was considered a significant risk, though further assessment is needed to determine ongoing exploit patterns.