cbcvebase.
CVE-2009-0088
published 2009-04-15

CVE-2009-0088: The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the…

PriorityP357critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
28.45%
97.9th percentile
The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftoffice_converter_pack
microsoftoffice_word
microsoftoffice_word
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.