← All CVEs

CVE-2007-1202

medium · 6.8

Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."

6.8
CVSS
29.5%
EPSS (exploit prob.)
98th
EPSS percentile
2007-05-08
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftword2000
microsoftword2002
microsoftword2003
microsoftword2004
microsoftword_viewer2003
microsoftworks2004
microsoftworks2005
microsoftworks2006

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-1202