Vulnerability Details CVE-2008-1092
Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.606
EPSS Ranking 98.2%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2008-1092
-
cpe:2.3:a:microsoft:word:2000
-
cpe:2.3:a:microsoft:word:2002
-
cpe:2.3:a:microsoft:word:2003
-
cpe:2.3:a:microsoft:word:2003_sp3
-
cpe:2.3:a:microsoft:word:2007
-
cpe:2.3:a:microsoft:word:2007_sp1
-
cpe:2.3:o:microsoft:windows_2000:-
-
cpe:2.3:o:microsoft:windows_2003_server:sp1
-
cpe:2.3:o:microsoft:windows_xp:-