First published: Tue Feb 12 2008(Updated: )
Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =xp-sp3 | |
Microsoft Office Word | ||
Microsoft Office | =2003-sp2 | |
Microsoft Office | =2003 | |
Microsoft Office | =2000-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0109 has a critical severity rating due to the potential for remote code execution.
To mitigate CVE-2008-0109, ensure that you apply the latest security patches and updates provided by Microsoft for affected Office versions.
CVE-2008-0109 affects Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Word Viewer 2003.
CVE-2008-0109 allows attackers to execute arbitrary code through crafted fields within the File Information Block in Word files.
Exploitation of CVE-2008-0109 can lead to memory corruption, which may give the attacker the ability to execute malicious code on the victim's system.