Vulnerability Name: | CVE-2010-2563 (CCN-61516) | ||||||||
Assigned: | 2010-09-14 | ||||||||
Published: | 2010-09-14 | ||||||||
Updated: | 2019-02-26 | ||||||||
Summary: | The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execute arbitrary code via a crafted document containing an unspecified value that is used in a loop counter, aka "WordPad Word 97 Text Converter Memory Corruption Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-2563 Source: IDEFENSE Type: UNKNOWN 20100914 Microsoft WordPad Word97 Converter Memory Corruption Vulnerability Source: CCN Type: SA41416 Microsoft Windows WordPad Text Converters Document Parsing Vulnerability Source: CCN Type: Microsoft Security Bulletin MS10-067 Vulnerability in WordPad Text Converters Could Allow Remote Code Execution (2259922) Source: CCN Type: Microsoft Security Bulletin MS11-033 Vulnerability in WordPad Text Converters Could Allow Remote Code Execution (2485663) Source: CCN Type: BID-43122 Microsoft WordPad Text Converter Word 97 File Parsing Memory Corruption Vulnerability Source: MS Type: UNKNOWN MS10-067 Source: XF Type: UNKNOWN ms-wordpad-word97-code-execution(61516) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:6632 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |