CVE-2008-3018: Code Injection
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file, aka the "Malformed PICT Filter Vulnerability," a different vulnerability than CVE-2008-3021.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3018?
CVE-2008-3018 has been classified with a critical severity level due to its potential to allow arbitrary code execution.
How do I fix CVE-2008-3018?
To mitigate CVE-2008-3018, it is recommended to update to the latest security patches for affected Microsoft Office products.
Which versions are affected by CVE-2008-3018?
CVE-2008-3018 affects Microsoft Office 2000 SP3, XP SP3, 2003 SP2, the Office Converter Pack, and Microsoft Works 8.
What type of vulnerability is CVE-2008-3018?
CVE-2008-3018 is a vulnerability related to improper parsing of PICT files that may lead to remote code execution.
Who can exploit CVE-2008-3018?
CVE-2008-3018 can be exploited by remote attackers through specially crafted PICT files.