First published: Tue Aug 12 2008(Updated: )
Microsoft Office 2000 SP3 and XP SP3; Office Converter Pack; and Works 8 do not properly parse the length of a BMP file, which allows remote attackers to execute arbitrary code via a crafted BMP file, aka the "Malformed BMP Filter Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Converter Pack | ||
Microsoft Office | =xp-sp3 | |
Microsoft Office | =2003-sp2 | |
Microsoft Works Suite | =8.0 | |
Microsoft Office | =2000-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-3020 is considered critical due to its potential to allow remote code execution.
To fix CVE-2008-3020, users should apply the latest security patches provided by Microsoft for affected Office and Works versions.
CVE-2008-3020 affects Microsoft Office 2000 SP3, Office XP SP3, and other related versions.
CVE-2008-3020 enables remote attackers to execute arbitrary code through a crafted BMP file.
Yes, Microsoft Works 8 is also impacted by CVE-2008-3020, making it vulnerable to exploitation.