cbcvebase.
CVE-2008-0108
published 2008-02-12

CVE-2008-0108: Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows…

PriorityP262critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
52.63%
98.9th percentile
Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftworks
microsoftworks

Detection & IOCsextracted from sources · hover to see the quote

filenamewkcvqd01.dll
bytes
\xd0\xcf\x11\xe0\xa1\xb1\x1a\xe1 (OLE compound document magic bytes, WPS file header)
bytes
\x43\x48\x4e\x4b\x57\x4b\x53\x20 (CHNKWKS section marker in malicious WPS)
bytes
\x18\x00\x54\x45\x58\x54 (TEXT section header with oversized field length in malicious WPS)
  • Attack vector is a malicious .wps file delivered to a victim; initial access is via social engineering (email attachment or download). Alert on .wps files opened by Office or Works processes that subsequently spawn child processes.
  • ·Affected products include Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005 — detections should cover all these variants, not just one.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.