ZDI-24-984: Microsoft Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-984?
ZDI-24-984 has a significant severity level as it allows remote code execution on vulnerable installations.
How do I fix ZDI-24-984?
To fix ZDI-24-984, ensure that Microsoft Word is updated to the latest version provided by Microsoft.
Who is affected by the ZDI-24-984 vulnerability?
Microsoft Word for Android users are affected by the ZDI-24-984 vulnerability.
What type of vulnerability is ZDI-24-984?
ZDI-24-984 is classified as a remote code execution vulnerability that requires user interaction.
Can ZDI-24-984 be exploited without user interaction?
No, ZDI-24-984 requires user interaction such as visiting a malicious page or opening a harmful file for exploitation.