Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xh93-p895-vcfc

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."

Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."

EPSS

Процентиль: 98%
0.57487
Средний

Дефекты

CWE-94

Связанные уязвимости

nvd
около 17 лет назад

Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."

EPSS

Процентиль: 98%
0.57487
Средний

Дефекты

CWE-94