Executive brief
A stack-based buffer overflow vulnerability in Microsoft Office allows remote attackers to execute arbitrary code via crafted RTF (Rich Text Format) data. The flaw exists in the parsing of RTF data across multiple versions of Office for Windows and Mac.
Affected products
- Microsoft Office XP SP3
- Microsoft Office 2003 SP3
- Microsoft Office 2007 SP2
- Microsoft Office 2010 All versions
- Microsoft Office 2004 for Mac All versions
- Microsoft Office 2008 for Mac All versions
- Microsoft Office for Mac 2011 All versions
- Microsoft Open XML File Format Converter for Mac All versions
Timeline
- 2010-11-09: advisory: Microsoft Security Bulletin MS10-087 published.
- 2010-11-09: patched: Microsoft released security updates to address the vulnerability.
- 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.