CVE-2007-0216

Microsoft Office - Improper Input Validation

Title source: rule

Description

wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."

Exploits (1)

exploitdb WORKING POC
clocalwindows
https://www.exploit-db.com/exploits/5107

Scores

EPSS 0.7127
EPSS Percentile 98.7%

Details

CWE
CWE-20
Status published
Products (3)
microsoft/office 2003 sp2 (2 CPE variants)
microsoft/works 8.0
microsoft/works 2005
Published Feb 12, 2008
Tracked Since Feb 18, 2026