CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
96.9%
The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka โWord 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability.โ
Vendor | Product | Version | CPE |
---|---|---|---|
microsoft | office_converter_pack | 2003 | cpe:2.3:a:microsoft:office_converter_pack:2003:*:*:*:*:*:*:* |
microsoft | office_word | 2000 | cpe:2.3:a:microsoft:office_word:2000:sp3:*:*:*:*:*:* |
microsoft | office_word | 2002 | cpe:2.3:a:microsoft:office_word:2002:sp3:*:*:*:*:*:* |
microsoft | windows_2000 | * | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* |
microsoft | windows_server_2003 | * | cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:* |
microsoft | windows_server_2003 | * | cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:* |
microsoft | windows_server_2003 | * | cpe:2.3:o:microsoft:windows_server_2003:*:sp1:itanium:*:*:*:*:* |
microsoft | windows_server_2003 | * | cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:* |
microsoft | windows_xp | * | cpe:2.3:o:microsoft:windows_xp:*:*:pro_x64:*:*:*:*:* |
microsoft | windows_xp | * | cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:* |
labs.idefense.com/intelligence/vulnerabilities/display.php?id=782
osvdb.org/53663
www.securitytracker.com/id?1022043
www.us-cert.gov/cas/techalerts/TA09-104A.html
www.vupen.com/english/advisories/2009/1024
docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-010
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5736