CVE-2008-4841

The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:microsoft:wordpad:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:wordpad:unknown:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*

History

21 Nov 2024, 00:52

Type Values Removed Values Added
References () http://milw0rm.com/sploits/2008-crash.doc.rar - Exploit () http://milw0rm.com/sploits/2008-crash.doc.rar - Exploit
References () http://secunia.com/advisories/32997 - Vendor Advisory () http://secunia.com/advisories/32997 - Vendor Advisory
References () http://securityreason.com/securityalert/4711 - () http://securityreason.com/securityalert/4711 -
References () http://securitytracker.com/id?1021376 - () http://securitytracker.com/id?1021376 -
References () http://www.microsoft.com/technet/security/advisory/960906.mspx - Vendor Advisory () http://www.microsoft.com/technet/security/advisory/960906.mspx - Vendor Advisory
References () http://www.securityfocus.com/bid/31399 - () http://www.securityfocus.com/bid/31399 -
References () http://www.securityfocus.com/bid/32718 - () http://www.securityfocus.com/bid/32718 -
References () http://www.us-cert.gov/cas/techalerts/TA09-104A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA09-104A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2008/3390 - () http://www.vupen.com/english/advisories/2008/3390 -
References () http://www.vupen.com/english/advisories/2009/1024 - () http://www.vupen.com/english/advisories/2009/1024 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-010 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-010 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6050 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6050 -
References () https://www.exploit-db.com/exploits/6560 - () https://www.exploit-db.com/exploits/6560 -

Information

Published : 2008-12-10 14:00

Updated : 2024-11-21 00:52


NVD link : CVE-2008-4841

Mitre link : CVE-2008-4841

CVE.ORG link : CVE-2008-4841


JSON object : View

Products Affected

microsoft

  • windows_server_2003
  • windows_2000
  • wordpad
  • windows_xp
CWE
CWE-399

Resource Management Errors

NVD-CWE-noinfo