Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
BID:31399
Info
Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
| Bugtraq ID: | 31399 |
| Class: | Unknown |
| CVE: |
CVE-2008-4841 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2008 12:00AM |
| Updated: | Apr 16 2015 05:54PM |
| Credit: | securfrog |
| Vulnerable: |
Microsoft WordPad 0 |
| Not Vulnerable: | |
Discussion
Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
WordPad is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue by enticing an unsuspecting victim to open a specially crafted '.doc' file.
Successfully exploiting this issue will cause the application to crash, denying service to legitimate users. Attackers may also be able to run arbitrary code, but this has not been confirmed.
WordPad is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue by enticing an unsuspecting victim to open a specially crafted '.doc' file.
Successfully exploiting this issue will cause the application to crash, denying service to legitimate users. Attackers may also be able to run arbitrary code, but this has not been confirmed.
Exploit / POC
Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
The following example '.doc' file is available:
The following example '.doc' file is available:
Solution / Fix
Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
References:
References:
- Vendor Home Page (Microsoft)