CVE-2012-0183Out-of-bounds Write in Microsoft Office

7 documents6 sources
Severity
9.3CRITICALNVD
EPSS
62.1%
top 1.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateMay 4

Description

Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDmicrosoft/word2003, 2007+1

🔴Vulnerability Details

2
GHSA
GHSA-8gx7-qfm6-j56p: Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execut2022-05-04
CVEList
CVE-2012-0183: Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execut2012-05-09

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows XP - Keyboard Layouts Pool Corruption (PoC) (MS12-034)2012-05-18

🔍Detection Rules

2
Suricata
ET WEB_CLIENT Microsoft Rich Text File download - SET2012-10-10
Suricata
ET WEB_CLIENT Hostile Microsoft Rich Text File (RTF) with corrupted listoverride2012-05-08

🕵️Threat Intelligence

1
Zscaler
Zscaler Protects against Microsoft's Patch Cycle | Round 9
CVE-2012-0183 — Out-of-bounds Write in Microsoft Office | cvebase