CVE ID | CVE-2008-4837 |
CVSS SCORE | |
AFFECTED VENDORS |
Microsoft |
AFFECTED PRODUCTS |
Office Word |
VULNERABILITY DETAILS |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Word. Exploitation requires that the attacker coerce the target into opening a malicious .DOC file. The specific flaw exists when processing a malformed table property within a Microsoft Word document. User-supplied data is copied into a stack-based buffer using a size that is calculated from the contents of the property. Exploitation can result in arbitrary code execution under the context of the current user. |
ADDITIONAL DETAILS |
Microsoft has issued an update to correct this vulnerability. More details can be found at:
http://www.microsoft.com/technet/security/bulletin/MS08-072.mspx |
DISCLOSURE TIMELINE |
|
CREDIT | wushi&ling of team509 |