First published: Thu Dec 16 2010(Updated: )
The FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted FlashPix image in an Office document, aka "FlashPix Image Converter Heap Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Converter Pack | ||
Microsoft Office | =xp-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3952 has a high severity rating due to its potential to allow remote code execution or denial of service.
To fix CVE-2010-3952, update Microsoft Office XP SP3 and the Office Converter Pack to the latest versions.
CVE-2010-3952 affects Microsoft Office XP SP3 and the Microsoft Office Converter Pack.
Yes, CVE-2010-3952 can potentially lead to data loss due to heap memory corruption.
The primary attack vector for CVE-2010-3952 is a crafted FlashPix image embedded in an Office document.