vendor:
Microsoft Office
by:
chujwamwdupe
7.5
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: Microsoft Office
Affected Version From: Microsoft Office 2003
Affected Version To: Microsoft Office 2003
Patch Exists: YES
Related CWE:
CPE: a:microsoft:office:2003
Platforms Tested: Microsoft Windows XP Service Pack 2
2008
Microsoft Works File Converter Remote Code Execution Vulnerability
A vulnerability exists in WPS to RTF convert filter that is part of Microsoft Office 2003. It could be exploited by a remote attacker to take complete control of an affected system. This issue is due to a stack overflow error in a function that reads sections from a WPS file. When the size of a section is changed to a number larger than 0x10, a stack overflow occurs - very easy to exploit.
Mitigation:
Apply the latest security patches from Microsoft to fix this vulnerability.