Junglewise Threat Intelligence

CVE-2010-3333: Microsoft Office Stack-based Buffer Overflow Vulnerability

CVE-2010-3333 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Office 2003. Vendors: Microsoft.

Executive brief

A stack-based buffer overflow vulnerability in Microsoft Office allows remote attackers to execute arbitrary code via crafted RTF (Rich Text Format) data. The flaw exists in the parsing of RTF data across multiple versions of Office for Windows and Mac.

Affected products

  • Microsoft Office XP SP3
  • Microsoft Office 2003 SP3
  • Microsoft Office 2007 SP2
  • Microsoft Office 2010 All versions
  • Microsoft Office 2004 for Mac All versions
  • Microsoft Office 2008 for Mac All versions
  • Microsoft Office for Mac 2011 All versions
  • Microsoft Open XML File Format Converter for Mac All versions

Timeline

  • 2010-11-09: advisory: Microsoft Security Bulletin MS10-087 published.
  • 2010-11-09: patched: Microsoft released security updates to address the vulnerability.
  • 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats