cbcvebase.
CVE-2008-0105
published 2008-02-12

CVE-2008-0105: Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a…

PriorityP258critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
43.76%
98.6th percentile
Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftworks
microsoftworks

Detection & IOCsextracted from sources · hover to see the quote

filenameevil.wps
bytes
43484e4b574b5320
bytes
18005445585400002f00
  • The malicious file uses the standard OLE2 Compound Document magic bytes (D0 CF 11 E0) with a crafted section header index table — scan for .wps files bearing this header combined with anomalous TEXT section size values (>0x10) in the CHNKWKS stream.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.