Unrated severityNVD Advisory· Published May 13, 2008· Updated Apr 23, 2026
CVE-2008-1091
CVE-2008-1091
Description
Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
Affected products
12cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2007:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2007_sp1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*
- cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007:*:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:office_compatibility_pack_for_word_excel_ppt_2007:*:*:sp1:*:*:*:*:*
cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:word_viewer:2003:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:word_viewer:2003:*:sp3:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/30143nvdVendor Advisory
- www.kb.cert.org/vuls/id/543907nvdUS Government Resource
- www.us-cert.gov/cas/techalerts/TA08-134A.htmlnvdUS Government Resource
- marc.infonvd
- www.securityfocus.com/archive/1/492020/100/0/threadednvd
- www.securityfocus.com/bid/29104nvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2008/1504/referencesnvd
- www.zerodayinitiative.com/advisories/ZDI-08-023nvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-026nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5494nvd
News mentions
0No linked articles in our index yet.