CVE-2009-0088: Input Validation
The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0088?
CVE-2009-0088 has a critical severity rating due to its potential to allow remote code execution.
How do I fix CVE-2009-0088?
To fix CVE-2009-0088, users should ensure that their Microsoft Office software is updated to the latest service pack.
What software is affected by CVE-2009-0088?
CVE-2009-0088 affects Microsoft Office Word 2000 SP3, Microsoft Office Converter Pack 2003, and several versions of Windows including Windows XP and Windows Server 2003.
Can CVE-2009-0088 be exploited remotely?
Yes, CVE-2009-0088 can be exploited remotely through specially crafted WordPerfect 6.x files.
What types of attacks can CVE-2009-0088 enable?
CVE-2009-0088 can enable attackers to execute arbitrary code on the affected systems.