CVE-2008-4841

The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:microsoft:wordpad:unknown:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:wordpad:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*

Information

Published : 2008-12-10 06:00

Updated : 2019-02-26 06:04


NVD link : CVE-2008-4841

Mitre link : CVE-2008-4841


JSON object : View

CWE
NVD-CWE-noinfo CWE-399

Resource Management Errors

Advertisement

dedicated server usa

Products Affected

microsoft

  • windows_xp
  • windows_server_2003
  • wordpad
  • windows_2000