TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
(MS08-072) Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173)
Vulnerability Identifier: CVE-2008-4024; CVE-2008-4025; CVE-2008-4026; CVE-2008-4027; CVE-2008-4030; CVE-2008-4028; CVE-2008-4031; CVE-2008-4837
Discovery Date: Dec 9, 2008
Risk: Critical
Affected Software:
  • Microsoft Office 2004 for Mac
  • Microsoft Office 2008 for Mac
  • Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
  • Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1
  • Microsoft Office Outlook 2007
  • Microsoft Office Outlook 2007 Service Pack 1
  • Microsoft Word 2000 Service Pack 3
  • Microsoft Word 2002 Service Pack 3
  • Microsoft Word 2003 Service Pack 3
  • Microsoft Word 2003 Viewer
  • Microsoft Word 2007
  • Microsoft Word 2007 Service Pack 1
  • Microsoft Word Viewer 2003 Service Pack 3
  • Microsoft Works 8.0
  • Open XML File Format Converter for Mac
Description:

This security update resolves eight privately reported vulnerabilities in Microsoft Office Word and Microsoft Office Outlook. The said vulnerabilities could allow remote code execution if a user opens a specially crafted Word or Rich Text Format (RTF) file.

A remote malicious user who successfully exploits these vulnerabilities could take complete control of an affected system. The said malicious user could then install programs; view, change, or delete data; or create new accounts with full user rights.

Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


Patch Information:

Patches for this vulnerability can be downloaded on this Microsoft Web page.
 
Search for another Security Advisory
Keyword: