Lucene search

K
cveMicrosoftCVE-2007-1202
HistoryMay 08, 2007 - 11:19 p.m.

CVE-2007-1202

2007-05-0823:19:00
CWE-20
microsoft
web.nvd.nist.gov
44
microsoft office
works suite
rtf parsing
vulnerability
cve-2007-1202

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.743

Percentile

98.1%

Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text “property strings of certain control words,” which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the “Word RTF Parsing Vulnerability.”

Affected configurations

Nvd
Node
microsoftwordMatch2000sp3
OR
microsoftwordMatch2002sp3
OR
microsoftwordMatch2003sp2
OR
microsoftwordMatch2004mac
OR
microsoftword_viewerMatch2003
OR
microsoftworksMatch2004
OR
microsoftworksMatch2005
OR
microsoftworksMatch2006
VendorProductVersionCPE
microsoftword2000cpe:2.3:a:microsoft:word:2000:sp3:*:*:*:*:*:*
microsoftword2002cpe:2.3:a:microsoft:word:2002:sp3:*:*:*:*:*:*
microsoftword2003cpe:2.3:a:microsoft:word:2003:sp2:*:*:*:*:*:*
microsoftword2004cpe:2.3:a:microsoft:word:2004:*:mac:*:*:*:*:*
microsoftword_viewer2003cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:*
microsoftworks2004cpe:2.3:a:microsoft:works:2004:*:*:*:*:*:*:*
microsoftworks2005cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*
microsoftworks2006cpe:2.3:a:microsoft:works:2006:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.743

Percentile

98.1%