First published: Thu Dec 16 2010(Updated: )
Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Converter Pack | ||
Microsoft Office | =xp-sp3 | |
Microsoft Office | =2003-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3946 has a critical severity rating as it allows remote attackers to execute arbitrary code.
To fix CVE-2010-3946, you should apply the latest security updates for Microsoft Office XP SP3, Office 2003 SP3, and the Office Converter Pack.
CVE-2010-3946 affects Microsoft Office XP SP3, Office 2003 SP3, and the Office Converter Pack.
Yes, a crafted PICT image in an Office document can be sent as an email attachment to exploit CVE-2010-3946.
The main risk of CVE-2010-3946 is that it can lead to remote code execution, potentially compromising the system.