CVE-2007-0515
published 2007-01-26CVE-2007-0515: Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word…
PriorityP268critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
38.16%
98.4th percentile
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word_viewer | — | — |
| microsoft | works | — | — |
| microsoft | works | — | — |
| microsoft | works | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Malicious Word 2000 (.doc) file exploiting a malformed string/function to corrupt memory and execute arbitrary code; flag suspicious .doc files opened by Word 2000 (version 9.0.2720) that spawn CMD.EXE as a child process. ↗
- →Exploit attempts against Word 2003/XP manifest as 100% CPU consumption (denial of service) rather than code execution — high CPU on WINWORD.EXE opening a .doc can indicate exploitation attempt. ↗
- →Signature family reference: track detections under the Exploit-MS06-027 variant family for this Word 2000 code-execution issue. ↗
- ·At time of exploit publication no patch was available (zero-day); verify current patch status before relying solely on signature-based detection. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gw2r-9wm8-vx4v: Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of servic
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-0515 [CRITICAL] GHSA-gw2r-9wm8-vx4v: Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of servic
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
GHSA
GHSA-fjhq-5r8j-6vg3: Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnera
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-0870 [CRITICAL] GHSA-fjhq-5r8j-6vg3: Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnera
Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
VulnCheck
Word Document Stream Vulnerability
vulncheck·2007·CVSS 9.3
CVE-2007-0870 [CRITICAL] Word Document Stream Vulnerability
Word Document Stream Vulnerability
Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
Affected: Microsoft Word
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024
VulnCheck
Word Malformed Function Vulnerability
vulncheck·2007·CVSS 9.3
CVE-2007-0515 [CRITICAL] Word Malformed Function Vulnerability
Word Malformed Function Vulnerability
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
No detection rules found.
Exploit-DB
Microsoft Word 2000 - Code Execution
exploitdb·2007-02-03
CVE-2007-0515 Microsoft Word 2000 - Code Execution
Microsoft Word 2000 - Code Execution
---
############ use at your own risk *******
+ Title: Microsoft Word 2000 Unspecified Code Execution Vulnerability Exploit (0-day)
+ code by xCuter (BongGoo Kang - [email protected])
+ Critical: High Critical
+ Impact: MS Word 2000 -> Could Allow Arbitrary Command Execution
MS word 2003 -> Attempts against Word 2003/XP will consume all CPU resources and will cause a denial of service
+ Where: From remote
+ Tested Operating System: Windows XP SP2 FULL PATCHED (Korean Language)
+ Tested Software: Microsoft(R) Word 2000 (9.0.2720)
+ Solution: Not Patched (zero-day)
+ Description:
When a user opens a specially crafted Word file using a malformed string,
it may corrupt system memory in such a way that an attacker could execute arbitrary code
Exploit-DB
Microsoft Word 2000 - Malformed Function Code Execution
exploitdb·2007-01-25
CVE-2007-0515 Microsoft Word 2000 - Malformed Function Code Execution
Microsoft Word 2000 - Malformed Function Code Execution
---
source: https://www.securityfocus.com/bid/22225/info
Microsoft Word 2000 is prone to a remote code-execution vulnerability.
Microsoft Word 2000 is confirmed vulnerable to a remote code-execution issue. Exploit attempts against Word 2003/XP will consume all CPU resources and will cause a denial of service for legitimate users.
Note that this issue is distinct from issues described in BID 21589 (Microsoft Word Code Execution Vulnerability), BID 21451 (Microsoft Word Malformed String Remote Code Execution Vulnerability), and BID 21518 (Microsoft Word Malformed Data Structures Code Execution Vulnerability).
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/29524.doc
No writeups or analysis indexed.
http://isc.sans.org/diary.html?storyid=2133http://osvdb.org/31900http://secunia.com/advisories/23950http://securitytracker.com/id?1017564http://www.kb.cert.org/vuls/id/412225http://www.microsoft.com/technet/security/advisory/932114.mspxhttp://www.securityfocus.com/bid/22225http://www.securityfocus.com/bid/22328http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.htmlhttp://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.htmlhttp://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&tabid=2http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlhttp://www.vupen.com/english/advisories/2007/0350https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014https://exchange.xforce.ibmcloud.com/vulnerabilities/31834https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A528http://isc.sans.org/diary.html?storyid=2133http://osvdb.org/31900http://secunia.com/advisories/23950http://securitytracker.com/id?1017564http://www.kb.cert.org/vuls/id/412225http://www.microsoft.com/technet/security/advisory/932114.mspxhttp://www.securityfocus.com/bid/22225http://www.securityfocus.com/bid/22328http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.htmlhttp://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.htmlhttp://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&tabid=2http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlhttp://www.vupen.com/english/advisories/2007/0350https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014https://exchange.xforce.ibmcloud.com/vulnerabilities/31834https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A528
2007-01-26
Published
Exploited in the wild