<< Back
CVE Number Vulnerability Product Severity Date
MS08-026 Vulnerabilities in Microsoft Word Could Allow Remote Code Execution(951207) Microsoft Office Critical 14-05-2008

Technical Information

Brief overview of the risk:
This security update resolves several privately reported vulnerabilities in Microsoft Word that could allow remote code execution if a user opens a specially crafted Word file.
Detailed Information on the risk:
A remote code execution vulnerability exists in the way that Microsoft Office handles specially crafted Rich Text Format (.rtf) files. The vulnerability could allow remote code execution if a user opens a specially crafted .rtf file with malformed strings in Word or previews a specially crafted .rtf file with malformed strings in rich text e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.Further information on this exploit is available at : MS08-026

Affected Software

Microsoft Office 2000 Service Pack 3
Microsoft Office 2003 Service Pack 2
Microsoft Office 2004 for Mac
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office XP Service Pack 3
Microsoft Word Viewer 2003
2007 Microsoft Office System