CVE-2008-3460: Critical severity microsoft office converter pack vulnerability
WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 does not properly parse the length of a WordPerfect Graphics (WPG) file, which allows remote attackers to execute arbitrary code via a crafted WPG file, aka the "WPG Image File Heap Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3460?
CVE-2008-3460 is considered critical due to its potential to allow remote code execution.
How do I fix CVE-2008-3460?
To fix CVE-2008-3460, ensure that you apply the latest security updates provided by Microsoft for the affected software versions.
Which software is affected by CVE-2008-3460?
CVE-2008-3460 affects Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Office Converter Pack, and Microsoft Works 8.
What kind of attacks can exploit CVE-2008-3460?
CVE-2008-3460 can be exploited through crafted WordPerfect Graphics (WPG) files leading to arbitrary code execution.
Is CVE-2008-3460 still a risk?
If you are using outdated versions of the affected Microsoft software without applying security patches, CVE-2008-3460 remains a significant risk.