First published: Tue Aug 12 2008(Updated: )
WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 does not properly parse the length of a WordPerfect Graphics (WPG) file, which allows remote attackers to execute arbitrary code via a crafted WPG file, aka the "WPG Image File Heap Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2000-sp3 | |
Microsoft Office | =2003-sp2 | |
Microsoft Office | =xp-sp3 | |
Microsoft Office Converter Pack | ||
Microsoft Works Suite | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3460 is considered critical due to its potential to allow remote code execution.
To fix CVE-2008-3460, ensure that you apply the latest security updates provided by Microsoft for the affected software versions.
CVE-2008-3460 affects Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Office Converter Pack, and Microsoft Works 8.
CVE-2008-3460 can be exploited through crafted WordPerfect Graphics (WPG) files leading to arbitrary code execution.
If you are using outdated versions of the affected Microsoft software without applying security patches, CVE-2008-3460 remains a significant risk.