Sploitus

Exploit for Microsoft Works File Converter field length buffer overflow

saint · 2008-02-19

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=SAINT:4E616B6AFE6882E27B3E5653C961F849
Added: 02/19/2008  
CVE: [CVE-2008-0108](<https://vulners.com/cve/CVE-2008-0108>)  
BID: [27659](<http://www.securityfocus.com/bid/27659>)  
OSVDB: [41459](<http://www.osvdb.org/41459>)  


### Background

The Microsoft Works File Converter allows [Microsoft Office](<http://office.microsoft.com>) to open [Microsoft Works](<http://www.microsoft.com/products/works>) files. 

### Problem

A buffer overflow vulnerability in the Microsoft Works File Converter allows arbitrary command execution when a user opens a `**.wps**` file with specially crafted field lengths. 

### Resolution

Apply the update referenced in [Microsoft Security Bulletin 08-011](<http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx>). 

### References

<http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx>  


### Limitations

Exploit works on Microsoft Word 2003 SP3 and requires a user to open the exploit file. 

### Platforms

Windows