CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS08-055 | Vulnerability in Microsoft Office Could Allow Remote Code Execution (955047) | Microsoft Office | Critical | 10-09-2008 |
Technical Information
Brief overview of the risk:
A remote code execution vulnerability exists in the way that Microsoft Office handles specially crafted URLs using the OneNote protocol handler (onenote://). The vulnerability could allow remote code execution if a user clicks a specially crafted OneNote URL.
Detailed Information on the risk:
An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.Further information on this exploit is available at : MS08-055
Affected Software
Microsoft Office 2003 Service Pack 2Microsoft Office 2003 Service Pack 3
Microsoft Office OneNote 2007
Microsoft Office OneNote 2007 Service Pack 1
Microsoft Office XP Service Pack 3
2007 Microsoft Office System
2007 Microsoft Office System Service Pack 1