Sploitus

Exploit for Microsoft Works File Converter index table vulnerability

saint · 2008-02-22

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=SAINT:7C8086F9B517ACDB5651EDFB20D50B32
Added: 02/22/2008  
CVE: [CVE-2008-0105](<https://vulners.com/cve/CVE-2008-0105>)  
BID: [27658](<http://www.securityfocus.com/bid/27658>)  
OSVDB: [41458](<http://www.osvdb.org/41458>)  


### Background

The Microsoft Works File Converter allows [Microsoft Office](<http://office.microsoft.com>) to open [Microsoft Works](<http://www.microsoft.com/products/works>) files. 

### Problem

A buffer overflow vulnerability in the Microsoft Works File Converter allows arbitrary command execution when a user opens a `**.wps**` file with a specially crafted index table. 

### Resolution

Apply the update referenced in [Microsoft Security Bulletin 08-011](<http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx>). 

### References

<http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx>  


### Limitations

Exploit works on Microsoft Word 2003 SP3 and requires a user to open the exploit file. 

### Platforms

Windows