First published: Thu Sep 15 2011(Updated: )
Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010 | |
Microsoft Office | =2010 | |
Microsoft Office | =2007-sp2 | |
Microsoft Office | =2010-sp1 | |
Microsoft Office | =2010-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1982 has a severity rating that indicates a high risk due to its potential to allow remote code execution.
To fix CVE-2011-1982, apply the latest security updates released by Microsoft for affected versions of Office.
CVE-2011-1982 affects Microsoft Office 2007 SP2, and Office 2010 Gold and SP1 for both x32 and x64 architectures.
CVE-2011-1982 facilitates remote code execution attacks through crafted Word documents.
CVE-2011-1982 is classified as a remote vulnerability that allows execution of arbitrary code.