Skip to main content

Microsoft Windows WordPad Converter Code Execution Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 5346 Views

RISK: Medium Risk

A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a memory corruption error in the WordPad Text Converter when processing a specially crafted Word 97 file (.doc, .wri, or .rtf extension), which could be exploited by attackers to execute arbitrary code by tricking a user into opening a malicious file.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Windows 2000 Service Pack 4
  • Microsoft Windows XP Service Pack 2
  • Microsoft Windows XP Professional x64 Edition
  • Microsoft Windows XP Professional x64 Edition Service Pack 2
  • Microsoft Windows Server 2003 Service Pack 1
  • Microsoft Windows Server 2003 Service Pack 2
  • Microsoft Windows Server 2003 SP1 (Itanium)
  • Microsoft Windows Server 2003 SP2 (Itanium)
  • Microsoft Windows Server 2003 x64 Edition
  • Microsoft Windows Server 2003 x64 Edition Service Pack 2

Solutions

There is no patch available for this vulnerability currently.


Vulnerability Identifier


Source


Related Link