CVE-2010-2748: Code Injection
Published Oct 13, 2010
·Updated
Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."
Affected Software
2 affected components
Microsoft Office=2004
Microsoft Word=2002-sp3
Event History
Oct 13, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2748?
CVE-2010-2748 is rated as critical due to its potential to allow remote code execution.
2
How do I fix CVE-2010-2748?
To fix CVE-2010-2748, apply the latest security updates provided by Microsoft for affected products.
3
What software is affected by CVE-2010-2748?
CVE-2010-2748 affects Microsoft Word 2002 SP3 and Microsoft Office 2004 for Mac.
4
What type of vulnerability is CVE-2010-2748?
CVE-2010-2748 is a boundary check vulnerability that leads to memory corruption.
5
Can CVE-2010-2748 be exploited by opening a document?
Yes, CVE-2010-2748 can be exploited by opening a specially crafted Word document.