← Back to CVE List
Vulnerability Intelligence Report

CVE-2009-0088

The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."

No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:28.45%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
microsoft office_converter_pack 2003
microsoft office_word 2000, 2002
microsoft windows_2000 all
microsoft windows_server_2003 all
microsoft windows_xp all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
28.446%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2009-01-08T00:00:00
Published2009-04-15T03:49:00
Patch Date2009-04-14
Last Updated2024-08-07T04:24:17

LINK COPIED TO CLIPBOARD