Tracker / CVE-2008-4024
CVE-2008-4024
High 9.3
Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
Affected products and versions
| microsoft | office |
|---|---|
| microsoft | office_compatibility_pack_for_word_excel_ppt_2007 |
| microsoft | office_outlook |
| microsoft | office_word |
| microsoft | office_word_viewer |
| microsoft | open_xml_file_format_converter |
| microsoft | works |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.