## https://sploitus.com/exploit?id=SAINT:4E616B6AFE6882E27B3E5653C961F849
Added: 02/19/2008
CVE: [CVE-2008-0108](<https://vulners.com/cve/CVE-2008-0108>)
BID: [27659](<http://www.securityfocus.com/bid/27659>)
OSVDB: [41459](<http://www.osvdb.org/41459>)
### Background
The Microsoft Works File Converter allows [Microsoft Office](<http://office.microsoft.com>) to open [Microsoft Works](<http://www.microsoft.com/products/works>) files.
### Problem
A buffer overflow vulnerability in the Microsoft Works File Converter allows arbitrary command execution when a user opens a `**.wps**` file with specially crafted field lengths.
### Resolution
Apply the update referenced in [Microsoft Security Bulletin 08-011](<http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx>).
### References
<http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx>
### Limitations
Exploit works on Microsoft Word 2003 SP3 and requires a user to open the exploit file.
### Platforms
Windows