CVE-2008-4024

EUVD-2008-4009
Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
microsoftoffice_compatibility_pack_for_word_excel_ppt_2007
*
microsoftoffice_compatibility_pack_for_word_excel_ppt_2007
*
microsoftopen_xml_file_format_converter
*
microsoftworks
8.0
𝑥
= Vulnerable software versions