Executive brief
Microsoft Word and related Office components are vulnerable to remote code execution or denial of service due to improper handling of crafted RTF data. The vulnerability, known as the 'listoverridecount' flaw, allows an attacker to cause memory corruption via a malicious document.
Affected products
- Microsoft Word 2003 SP3
- Microsoft Word 2007 SP2, SP3
- Microsoft Word 2010 SP1
- Microsoft Word Viewer
- Microsoft Office Compatibility Pack SP2, SP3
- Microsoft Office Web Apps 2010 SP1
Timeline
- 2012-12-11: disclosed: NVD Published Date
- 2012-12-11: patched: Microsoft Security Bulletin MS12-079 released
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-28: exploited: Confirmed exploited in the wild per CISA KEV catalog entry