Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-1202 | First vendor Publication | 2007-05-08 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1202 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:1900 | |||
Oval ID: | oval:org.mitre.oval:def:1900 | ||
Title: | Word RTF Parsing Vulnerability | ||
Description: | Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2007-1202 | Version: | 7 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 | Product(s): | Microsoft Word |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 4 | |
Application | 1 | |
Application | 3 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
34388 | Microsoft Word RTF Rich Text Properties Parsing Remote Code Execution Microsoft Word 2003 SP2 (winword.exe file version 11.0.8106.0) contains a flaw that may allow remote code execution. The issue is due to a heap corruption vulnerability in Word, specifically in the handling of property strings in RTF documents. Exploitation requires a target user to load a specially crafted RTF document. When loaded, arbitrary code may be executed with the same permissions as the target user. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-05-09 | Name : An application installed on the remote Mac OS X host is affected by multiple ... File : macosx_ms_office_may2007.nasl - Type : ACT_GATHER_INFO |
2007-05-08 | Name : Arbitrary code can be executed on the remote host through Microsoft Word. File : smb_nt_ms07-024.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:17:27 |
|
2024-11-28 12:11:40 |
|
2021-05-04 12:05:27 |
|
2021-04-22 01:06:00 |
|
2020-05-23 00:19:22 |
|
2018-10-16 21:19:51 |
|
2018-10-13 00:22:36 |
|
2017-10-11 09:23:52 |
|
2016-06-28 16:15:11 |
|
2016-04-26 15:49:27 |
|
2014-02-17 10:39:16 |
|
2013-05-11 10:20:01 |
|