Vulnerabilities > CVE-2005-0558 - Unspecified vulnerability in Microsoft Word 2000/2002/2003
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS05-023.NASL |
description | The remote host is running a version of Microsoft Word that could allow arbitrary code to be run. To succeed, the attacker would have to send a rogue Word file to a user of the remote computer and have it open it. Then the macros contained in the Word file would bypass the security model of Word, and would be executed. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18026 |
published | 2005-04-12 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18026 |
title | MS05-023: Vulnerability in Word May Lead to Code Execution (890169) |
code |
|
Oval
accepted 2013-02-18T04:00:07.956-05:00 class vulnerability contributors name Matthew Burton organization The MITRE Corporation name John Hoyland organization Centennial Software name Chris Wood organization Assuria Ltd. name Sharath S organization SecPod Technologies name Shane Shaffer organization G2, Inc. name Sergey Artykhov organization ALTX-SOFT
description Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document. family windows id oval:org.mitre.oval:def:1236 status accepted submitted 2005-09-15T04:00:00.000-04:00 title Word 2003 (wordview) Malicious .doc Buffer Overflow II version 11 accepted 2012-05-28T04:01:34.810-04:00 class vulnerability contributors name Matthew Burton organization The MITRE Corporation name John Hoyland organization Centennial Software name Shane Shaffer organization G2, Inc.
description Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document. family windows id oval:org.mitre.oval:def:2415 status accepted submitted 2005-09-15T04:00:00.000-04:00 title Word 2002 Malicious .doc Buffer Overflow II version 5 accepted 2012-05-28T04:01:35.922-04:00 class vulnerability contributors name Matthew Burton organization The MITRE Corporation name John Hoyland organization Centennial Software name Shane Shaffer organization G2, Inc.
description Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document. family windows id oval:org.mitre.oval:def:2685 status accepted submitted 2005-09-15T04:00:00.000-04:00 title Word 2000 Malicious .doc Buffer Overflow II version 5 accepted 2012-05-28T04:01:42.902-04:00 class vulnerability contributors name Matthew Burton organization The MITRE Corporation name John Hoyland organization Centennial Software name Shane Shaffer organization G2, Inc.
description Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document. family windows id oval:org.mitre.oval:def:4234 status accepted submitted 2005-09-15T04:00:00.000-04:00 title Word 2003 Malicious .doc Buffer Overflow II version 5
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-023
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19828
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1236
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2415
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2685
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4234