First published: Wed Nov 11 2009(Updated: )
Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka "Microsoft Office Word File Information Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Open XML File Format Converter | ||
Microsoft Office | =2008 | |
Microsoft Office | =2004 | |
Microsoft Office Word Viewer | =2003-sp3 | |
Microsoft Office Word | =2002-sp3 | |
Microsoft Office Word Viewer | ||
Microsoft Office Word | =2003-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3135 has a high severity rating due to its potential to allow remote code execution.
To fix CVE-2009-3135, users should update Microsoft Office and Office Word Viewer to the latest available patches.
CVE-2009-3135 affects Microsoft Office Word 2002 SP3, 2003 SP3, Office 2004 and 2008 for Mac, and Office Word Viewer 2003 SP3.
Yes, CVE-2009-3135 can be exploited remotely by attackers through specially crafted Word documents.
CVE-2009-3135 is associated with attacks that involve buffer overflows leading to arbitrary code execution.