First published: Wed Dec 12 2012(Updated: )
Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Word | ||
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Web Apps | =2010-sp1 | |
Microsoft Word Viewer | ||
Microsoft Office Word | =2003-sp3 | |
Microsoft Office Word | =2007-sp2 | |
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2010-sp1 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Word Viewer | ||
Microsoft SharePoint Server 2010 | =2010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2539 has been classified as a critical vulnerability that allows remote code execution.
To fix CVE-2012-2539, users should apply the latest security updates from Microsoft for the affected versions of Microsoft Word and the Office Compatibility Pack.
CVE-2012-2539 affects Microsoft Word 2003 SP3, 2007 SP2 and SP3, 2010 SP1, Word Viewer, and Office Compatibility Pack SP2 and SP3.
Users of Microsoft Word and Office products listed in the CVE-2012-2539 advisory are vulnerable if they are using the affected versions without applying the necessary updates.
CVE-2012-2539 can be exploited through crafted RTF data to execute arbitrary code or cause memory corruption, leading to denial of service.