CVE-2008-1091: Code Injection
Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1091?
CVE-2008-1091 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-1091?
To mitigate CVE-2008-1091, update Microsoft Office to the latest security patches from Microsoft.
What versions of Microsoft software are affected by CVE-2008-1091?
CVE-2008-1091 affects Microsoft Office versions 2000 SP3, XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier.
What type of file can trigger CVE-2008-1091?
CVE-2008-1091 can be triggered by a malformed Rich Text Format (.rtf) file.
What kind of attack can CVE-2008-1091 facilitate?
CVE-2008-1091 allows remote attackers to execute arbitrary code on affected systems.