First published: Wed Apr 15 2009(Updated: )
Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp2 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows 2003 Server | =sp1 | |
Microsoft Windows 2003 Server | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0235 is considered a critical vulnerability due to its potential for arbitrary code execution.
To fix CVE-2009-0235, you should apply the latest security patches and updates provided by Microsoft for the affected operating systems.
CVE-2009-0235 affects Microsoft Windows 2000 SP4, Windows XP SP2, Windows XP SP3, and Windows Server 2003 SP1 and SP2.
CVE-2009-0235 enables remote attackers to execute arbitrary code through crafted Word 97 files.
The best practice is to apply security updates, but users can also avoid opening untrusted Word 97 files as a temporary workaround.