CVE-2004-0848

Description

Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) %00 (null byte) in .doc filenames or (2) %0a (carriage return) in .rtf filenames.

Risk Information

Base Score
7.7
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
43.043

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Office XP (KB873352)Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234