CVE-2008-3007: Input Validation
Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3007?
CVE-2008-3007 has a high severity rating as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2008-3007?
To mitigate CVE-2008-3007, users should apply the latest security patches provided by Microsoft for the affected Office versions.
Which versions of Microsoft Office are affected by CVE-2008-3007?
CVE-2008-3007 affects Microsoft Office XP SP3, 2003 SP2 and SP3, and 2007 Office System including OneNote 2007.
What type of attack is associated with CVE-2008-3007?
CVE-2008-3007 facilitates a remote code execution attack via crafted onenote:// URLs.
Can CVE-2008-3007 be exploited without user interaction?
Exploitation of CVE-2008-3007 typically requires user interaction, such as clicking a malicious link.