A memory corruption vulnerability exists in the WordPad Text Converter for Word 97 which may allow for remote code execution.
A memory corruption vulnerability exists in the WordPad Text Converter for Word 97 which may allow for remote code execution. Successful exploitation would require that a user open a specially-crafted .doc or .rtf file within WordPad. Once opened, memory can become corrupted in a way which may allow for the execution of arbitrary code.
Attack VectorMaliciously Crafted File
User Interactionuser interaction is needed
Vendor StatusResponded and patched
Vulnerable Systems
Windows 2003 x64
SP2,
A proof of concept has been released.
2008-12-09Vendor has provided information on the vulnerability.
2009-04-14Vendor has provided a patch.
The vendor has released a patch to address this issue:
http://www.microsoft.com/technet/security/bulletin/ms09-010.mspx
Vulnerabilities in WordPad and Office Text Converters could allow Remote Code Execution (960477)
http://www.microsoft.com/technet/security/bulletin/ms09-010.mspx