First published: Tue Aug 12 2008(Updated: )
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file, aka the "Malformed PICT Filter Vulnerability," a different vulnerability than CVE-2008-3021.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | =xp-sp3 | |
Microsoft Office | =2000-sp3 | |
Microsoft Office Converter Pack | ||
Microsoft Works | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3018 has been classified with a critical severity level due to its potential to allow arbitrary code execution.
To mitigate CVE-2008-3018, it is recommended to update to the latest security patches for affected Microsoft Office products.
CVE-2008-3018 affects Microsoft Office 2000 SP3, XP SP3, 2003 SP2, the Office Converter Pack, and Microsoft Works 8.
CVE-2008-3018 is a vulnerability related to improper parsing of PICT files that may lead to remote code execution.
CVE-2008-3018 can be exploited by remote attackers through specially crafted PICT files.