Unrated severityNVD Advisory· Published May 8, 2007· Updated Jun 16, 2026
CVE-2007-1202
CVE-2007-1202
Description
Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:microsoft:word:2000:sp3:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:microsoft:word:2000:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:word:2002:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:word:2003:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:word:2004:*:mac:*:*:*:*:*
- (no CPE)range: 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, Works Suite 2004, 2005, 2006
- cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- labs.idefense.com/intelligence/vulnerabilities/display.phpnvdPatch
- www.securityfocus.com/bid/23836nvdPatch
- www.securitytracker.com/idnvdPatch
- www.vupen.com/english/advisories/2007/1709nvdVendor Advisory
- www.kb.cert.org/vuls/id/555489nvdUS Government Resource
- www.us-cert.gov/cas/techalerts/TA07-128A.htmlnvdUS Government Resource
- www.osvdb.org/34388nvd
- www.securityfocus.com/archive/1/468871/100/200/threadednvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1900nvd
News mentions
0No linked articles in our index yet.