CVE-2008-4024: Code Injection
Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4024?
CVE-2008-4024 is classified as critical due to its potential to allow remote code execution.
How do I fix CVE-2008-4024?
To fix CVE-2008-4024, users should update their Microsoft Office software to the latest available patches.
Which versions of Microsoft Office are affected by CVE-2008-4024?
CVE-2008-4024 affects Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, 2004 for Mac, and 2008 for Mac.
Can CVE-2008-4024 be exploited through email attachments?
Yes, CVE-2008-4024 can be exploited through malicious Word documents sent as email attachments.
Is there a workaround for CVE-2008-4024 if I cannot update immediately?
As a temporary workaround for CVE-2008-4024, users should avoid opening untrusted Word documents.