CVE-2007-0515: Critical severity Microsoft Works vulnerability

Published Jan 26, 2007
·
Updated

Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.

Affected Software

11 affected components
Microsoft Works=2006
Microsoft Office=2004
Microsoft Word=2000
Microsoft Office=xp-sp3
Microsoft Office=2003-sp2
Microsoft Word=2003
Microsoft Works=2005
Microsoft Word=2002
Microsoft Word Viewer=2003
Microsoft Works=2004
Microsoft Office=2000-sp3

Event History

Jan 26, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2007-0515?

CVE-2007-0515 has been rated as critical due to its potential for remote code execution and denial of service.

2

How do I fix CVE-2007-0515?

To mitigate CVE-2007-0515, it is recommended to update Microsoft Word and related software to the latest versions available.

3

What platforms are affected by CVE-2007-0515?

CVE-2007-0515 affects various versions of Microsoft Word, Microsoft Office, and Microsoft Works, including Word 2000 through 2003.

4

What types of attacks exploit CVE-2007-0515?

CVE-2007-0515 can be exploited through user-assisted attacks involving specially crafted documents that trigger memory corruption.

5

What are the symptoms of exploitation of CVE-2007-0515?

Exploitation of CVE-2007-0515 may result in arbitrary code execution on the affected system or cause the application to crash.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203