9.3

CVE-2009-0563

Warning

Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftOffice Version2000 Updatesp3
MicrosoftOffice Version2003 Updatesp3
MicrosoftOffice Version2004 SwPlatformmacos
MicrosoftOffice Version2007 Updatesp1
MicrosoftOffice Version2007 Updatesp2
MicrosoftOffice Version2008 SwPlatformmacos
MicrosoftOffice Versionxp Updatesp3
MicrosoftOffice Compatibility Pack Version2007 Updatesp1
MicrosoftOffice Compatibility Pack Version2007 Updatesp2
MicrosoftOffice Word Viewer Version2003 Updatesp3
MicrosoftOpen Xml File Format Converter Version- SwPlatformmacos

08.06.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Office Buffer Overflow Vulnerability

Vulnerability

Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 80.02% 0.991
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.