CVE-2012-2550
published 2012-10-09CVE-2012-2550: Microsoft Works 9 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Word .doc file, aka…
PriorityP350critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
22.17%
97.4th percentile
Microsoft Works 9 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Word .doc file, aka "Works Heap Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | works | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: Microsoft Works 9 parsing a specially crafted Word .doc file causes heap memory corruption, enabling remote code execution. ↗
- →File type to inspect/block at perimeter or endpoint: malicious Word .doc files targeting Microsoft Works 9. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/50844http://www.securityfocus.com/bid/55796http://www.securitytracker.com/id?1027621http://www.us-cert.gov/cas/techalerts/TA12-283A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-065http://secunia.com/advisories/50844http://www.securityfocus.com/bid/55796http://www.securitytracker.com/id?1027621http://www.us-cert.gov/cas/techalerts/TA12-283A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-065
2012-10-09
Published