First published: Wed Oct 13 2010(Updated: )
Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Word | =2002-sp3 | |
Microsoft Office | =2004 | |
Microsoft Office Word | =2003-sp3 | |
Microsoft Office Word Viewer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3221 has a critical severity rating as it allows remote code execution on vulnerable systems.
To fix CVE-2010-3221, users should apply the latest security updates provided by Microsoft for the affected versions of Word and Office.
CVE-2010-3221 affects Microsoft Word 2002 SP3, 2003 SP3, Office 2004 for Mac, and the Word Viewer.
The implications of CVE-2010-3221 include the potential for attackers to execute arbitrary code on affected systems by exploiting a specially crafted document.
A temporary workaround for CVE-2010-3221 is to avoid opening untrusted Word documents until the software can be updated.