Vulnerabilities > CVE-2004-0573 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
Vulnerable Configurations
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS04-027.NASL |
description | The remote host is running a version of Microsoft Office that contains a flaw in its WordPerfect converter, that could allow an attacker to execute arbitrary code on the remote host. To exploit this flaw, an attacker would need to send a specially crafted file to a user on the remote host and wait for him to open it using Microsoft Office. When opening the malformed file, Microsoft Office will encounter a buffer overflow that could be exploited to execute arbitrary code. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14732 |
published | 2004-09-15 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14732 |
title | MS04-027: Vulnerability in WordPerfect Converter (884933) |
code |
|
Oval
accepted 2014-01-20T04:01:18.900-05:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name John Hoyland organization Centennial Software name Dragos Prisaca organization G2, Inc.
description Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website. family windows id oval:org.mitre.oval:def:2670 status accepted submitted 2004-09-28T12:00:00.000-04:00 title Office 2000 WordPerfect Converter Buffer Overflow version 10 accepted 2014-01-20T04:01:19.026-05:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name Jonathan Baker organization The MITRE Corporation name Dragos Prisaca organization G2, Inc.
definition_extensions comment Microsoft Office 2003 is installed oval oval:org.mitre.oval:def:233 description Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website. family windows id oval:org.mitre.oval:def:3311 status accepted submitted 2004-09-23T12:00:00.000-04:00 title Office 2003 WordPerfect Converter Buffer Overflow version 11 accepted 2014-01-20T04:01:19.137-05:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name Dragos Prisaca organization G2, Inc.
description Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website. family windows id oval:org.mitre.oval:def:3333 status accepted submitted 2004-09-22T12:00:00.000-04:00 title Office XP, SP3 WordPerfect Converter Buffer Overflow version 9 accepted 2014-01-20T04:01:19.205-05:00 class vulnerability contributors name Ingrid Skoog organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name Dragos Prisaca organization G2, Inc.
description Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website. family windows id oval:org.mitre.oval:def:4005 status accepted submitted 2004-09-22T12:00:00.000-04:00 title Office XP, SP2 WordPerfect Converter Buffer Overflow version 9 accepted 2007-11-13T12:01:18.060-05:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name John Hoyland organization Centennial Software name Jeff Cheng organization Opsware, Inc.
description The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows. family windows id oval:org.mitre.oval:def:5021 status accepted submitted 2004-10-13T12:21:00.000-04:00 title Vulnerability in NNTP Could Allow Remote Code Execution version 31
References
- http://www.kb.cert.org/vuls/id/449438
- http://securitytracker.com/id?1011249
- http://securitytracker.com/id?1011250
- http://securitytracker.com/id?1011251
- http://securitytracker.com/id?1011252
- http://secunia.com/advisories/12529
- http://marc.info/?l=bugtraq&m=109519646030906&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17306
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5021
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4005
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3333
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3311
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2670
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-027