6.8

CVE-2007-1202

Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWord Version2000 Updatesp3
MicrosoftWord Version2002 Updatesp3
MicrosoftWord Version2003 Updatesp2
MicrosoftWord Version2004 Editionmac
MicrosoftWord Viewer Version2003
MicrosoftWorks Version2004
MicrosoftWorks Version2005
MicrosoftWorks Version2006
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 58.16% 0.981
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.