Heap Corruption Vulnerability in Microsoft Office Products
CVE-2008-3460

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 August 2008

What is CVE-2008-3460?

The vulnerability in the WPGIMP32.FLT component of Microsoft Office products enables attackers to exploit improper parsing of the length of a WordPerfect Graphics (WPG) file. This flaw can result in remote code execution, allowing a malicious entity to carry out arbitrary commands on an affected system when a user opens a specially crafted WPG file. This highlights the importance of diligent file handling and maintaining updated versions of affected software to mitigate potential risks.

References

EPSS Score

60% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2008-3460 : Heap Corruption Vulnerability in Microsoft Office Products