<< Back
CVE Number Vulnerability Product Severity Date
MS08-055 Vulnerability in Microsoft Office Could Allow Remote Code Execution (955047) Microsoft Office Critical 10-09-2008

Technical Information

Brief overview of the risk:
A remote code execution vulnerability exists in the way that Microsoft Office handles specially crafted URLs using the OneNote protocol handler (onenote://). The vulnerability could allow remote code execution if a user clicks a specially crafted OneNote URL.
Detailed Information on the risk:
An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.Further information on this exploit is available at : MS08-055

Affected Software

Microsoft Office 2003 Service Pack 2
Microsoft Office 2003 Service Pack 3
Microsoft Office OneNote 2007
Microsoft Office OneNote 2007 Service Pack 1
Microsoft Office XP Service Pack 3
2007 Microsoft Office System
2007 Microsoft Office System Service Pack 1