CVE-2012-0182: Code Injection
Published Oct 9, 2012
·Updated
Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."
Affected Software
2 affected components
Microsoft Word=2007-sp2
Microsoft Word=2007-sp3
Event History
Oct 9, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0182?
CVE-2012-0182 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2012-0182?
To fix CVE-2012-0182, users should install the latest security updates provided by Microsoft for Word 2007 SP2 and SP3.
3
What are the risks associated with CVE-2012-0182?
CVE-2012-0182 allows attackers to execute arbitrary code, potentially compromising system integrity and data.
4
Which versions of Microsoft Word are affected by CVE-2012-0182?
CVE-2012-0182 affects Microsoft Word 2007 Service Pack 2 and Service Pack 3.
5
Can CVE-2012-0182 be exploited through a phishing attack?
Yes, CVE-2012-0182 can be exploited via phishing attacks where a user opens a maliciously crafted Word document.