SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-1533

Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers…

HIGH 9.3EPSS 35.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 35.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
35.62% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
microsoft/office · microsoft/office xp · microsoft/works
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.