Lucene search

K
cve[email protected]CVE-2010-3334
HistoryNov 10, 2010 - 3:00 a.m.

CVE-2010-3334

2010-11-1003:00:02
CWE-119
web.nvd.nist.gov
28
cve-2010-3334
microsoft office
remote code execution
memory corruption
nvd
vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.954 High

EPSS

Percentile

99.4%

Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Office document containing an Office Art Drawing record with crafted msofbtSp records and unspecified flags, which triggers memory corruption, aka โ€œOffice Art Drawing Records Vulnerability.โ€

Affected configurations

NVD
Node
microsoftofficeMatch2003sp3
OR
microsoftofficeMatch2004mac
OR
microsoftofficeMatch2007sp2
OR
microsoftofficeMatch2008mac
OR
microsoftofficeMatch2010
OR
microsoftofficeMatch2011mac
OR
microsoftofficeMatchxpsp3
OR
microsoftopen_xml_file_format_convertermac

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.954 High

EPSS

Percentile

99.4%