CVE-2008-4030
Summary
| CVE | CVE-2008-4030 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-12-10 14:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1 allow remote attackers to execute arbitrary code via crafted control words in (1) an RTF file or (2) a rich text e-mail message, which triggers incorrect memory allocation and memory corruption, aka "Word RTF Object Parsing Vulnerability," a different vulnerability than CVE-2008-4028. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office | 2000 | sp3 | All | All |
| Application | Microsoft | Office | 2003 | sp3 | All | All |
| Application | Microsoft | Office | xp | sp3 | All | All |
| Application | Microsoft | Office | 2004 | All | mac | All |
| Application | Microsoft | Office | 2008 | All | mac | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | All | All | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | sp1 | All | All |
| Application | Microsoft | Office Outlook | 2007 | All | All | All |
| Application | Microsoft | Office Outlook | 2007 | sp1 | All | All |
| Operating System | Microsoft | Office System | All | 2007 | All | All |
| Operating System | Microsoft | Office System | sp1 | 2007 | All | All |
| Application | Microsoft | Office Word | 2000 | sp3 | All | All |
| Application | Microsoft | Office Word | 2002 | sp3 | All | All |
| Application | Microsoft | Office Word | 2003 | sp3 | All | All |
| Application | Microsoft | Office Word | 2007 | All | All | All |
| Application | Microsoft | Office Word Viewer | 2003 | All | All | All |
| Application | Microsoft | Office Word Viewer | 2003 | sp3 | All | All |
| Application | Microsoft | Open Xml File Format Converter | All | All | mac | All |
| Application | Microsoft | Works | 8.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| US-CERT Technical Cyber Security Alert TA08-344A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Microsoft Security Bulletin MS08-072 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Microsoft Word Memory Corruption Errors Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.