Executive brief
A stack-based buffer overflow vulnerability exists in multiple versions of Microsoft Office Word and related components. Remote attackers can execute arbitrary code by tricking a user into opening a specially crafted Word document containing a tag with an invalid length field.
Affected products
- Microsoft Office Word 2002 SP3
- Microsoft Office Word 2003 SP3
- Microsoft Office Word 2007 SP1, SP2
- Microsoft Office for Mac 2004
- Microsoft Office for Mac 2008
- Microsoft Open XML File Format Converter for Mac
- Microsoft Office Word Viewer 2003 SP3
- Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1, SP2
Timeline
- 2009-06-09: patched: Microsoft Security Bulletin MS09-027 published.
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-06-08: disclosed: NVD publication date.