Home→Descriptions→SA30975
| Secunia ID | |
| CVE-ID | |
| Release Date |
09 Jul 2008 |
| Last Change |
12 Aug 2008 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Microsoft Office 2003 Professional Edition |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been discovered in Microsoft Word, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error in the processing of smart tag length values, which can be exploited to cause memory corruption via a specially crafted document. Successful exploitation allows execution of arbitrary code. NOTE: According to the vendor, the vulnerability is currently being actively exploited. |
| Solution |
Apply patches. Microsoft Word 2002 SP3: Microsoft Word 2003 SP2: Microsoft Word 2003 SP3: |
| Reported by |
Reported as a 0-day. |
| Original Advisory |
MS08-042 (KB955048): Microsoft: |