9.3
CVSSv2

CVE-2008-0108

Published: 12/02/2008 Updated: 12/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote malicious users to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft office 2003

microsoft works 2005

microsoft works 8.0

Exploits

/* * Copyright (c) 2008 chujwamwdupe - pumpernikielc * * one day in teletubby land * * an email from idefense: * * "Unfortunately, Microsoft has refused to credit you using the name you requested" * * what's wrong with 'chujwamwdupe', eh? * * * Description: * A vulnerability exists in WPS to RTF convert filter that is part * of Micro ...
source: wwwsecurityfocuscom/bid/27659/info Microsoft Works File Converter is prone to a remote code-execution vulnerability because it fails to adequately validate user-supplied input An attacker could exploit this issue by enticing a victim to open a malicious 'wps' file Successfully exploiting this issue would allow the attacker to ...