9.3 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
0.934 High
EPSS
Percentile
99.1%
Added: 12/14/2010
CVE: CVE-2010-3951
BID: 45278
OSVDB: 69808
Microsoft Office is a package that provides word processing, spreadsheet, presentation, e-mail, and calendaring capabilities for Microsoft Windows workstations. The suite ships with a set of image processing helper libraries known as graphics filters that support various image formats including FlashPix (FPX).
A buffer overflow vulnerability in the way Microsoft Office handles FlashPix image files allows remote attackers to execute arbitrary code by enticing a user to insert a malicious FlashPix image file into an Office document.
Apply the patches referenced in Microsoft Security Bulletin 10-105.
<http://secunia.com/advisories/35600/>
Exploit works on Microsoft Office XP SP3 and requires the user to insert the FPX image file in a Word document.
Windows XP