CVE-2008-3018

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
12/08/2008
Last modified:
09/04/2025

Description

Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file, aka the "Malformed PICT Filter Vulnerability," a different vulnerability than CVE-2008-3021.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:windows_nt:xp:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_converter_pack:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:works:8.0:*:*:*:*:*:*:*