Heap Corruption Vulnerability in Microsoft Office Products
CVE-2008-3460
Currently unrated
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 12 August 2008
What is CVE-2008-3460?
The vulnerability in the WPGIMP32.FLT component of Microsoft Office products enables attackers to exploit improper parsing of the length of a WordPerfect Graphics (WPG) file. This flaw can result in remote code execution, allowing a malicious entity to carry out arbitrary commands on an affected system when a user opens a specially crafted WPG file. This highlights the importance of diligent file handling and maintaining updated versions of affected software to mitigate potential risks.
References
EPSS Score
60% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved