CVE-2008-0105
published 2008-02-12CVE-2008-0105: Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a…
PriorityP258critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
43.76%
98.6th percentile
Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | works | — | — |
| microsoft | works | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
43484e4b574b5320
bytes↗
18005445585400002f00
- →The malicious file uses the standard OLE2 Compound Document magic bytes (D0 CF 11 E0) with a crafted section header index table — scan for .wps files bearing this header combined with anomalous TEXT section size values (>0x10) in the CHNKWKS stream. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=120361015026386&w=2http://secunia.com/advisories/28904http://www.securityfocus.com/bid/27658http://www.securitytracker.com/id?1019387http://www.us-cert.gov/cas/techalerts/TA08-043C.htmlhttp://www.vupen.com/english/advisories/2008/0513/referenceshttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-011https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5009http://marc.info/?l=bugtraq&m=120361015026386&w=2http://secunia.com/advisories/28904http://www.securityfocus.com/bid/27658http://www.securitytracker.com/id?1019387http://www.us-cert.gov/cas/techalerts/TA08-043C.htmlhttp://www.vupen.com/english/advisories/2008/0513/referenceshttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-011https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5009
2008-02-12
Published