CVE-2011-1982

Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2010:*:x32:*:*:*:*:*
cpe:2.3:a:microsoft:office:2010:*:x64:*:*:*:*:*
cpe:2.3:a:microsoft:office:2010:sp1:x32:*:*:*:*:*
cpe:2.3:a:microsoft:office:2010:sp1:x64:*:*:*:*:*

History

21 Nov 2024, 01:27

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/909022 - US Government Resource () http://www.kb.cert.org/vuls/id/909022 - US Government Resource
References () http://www.us-cert.gov/cas/techalerts/TA11-256A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA11-256A.html - US Government Resource
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-073 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-073 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12243 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12243 -

Information

Published : 2011-09-15 12:26

Updated : 2024-11-21 01:27


NVD link : CVE-2011-1982

Mitre link : CVE-2011-1982

CVE.ORG link : CVE-2011-1982


JSON object : View

Products Affected

microsoft

  • office
CWE
CWE-20

Improper Input Validation