CVE-2008-0108

Microsoft Office - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."

Exploits (2)

exploitdb WORKING POC VERIFIED
by chujwamwdupe · clocalwindows
https://www.exploit-db.com/exploits/5107
exploitdb WORKING POC VERIFIED
by Luigi Auriemma · cremotewindows
https://www.exploit-db.com/exploits/31118

Scores

EPSS 0.7542
EPSS Percentile 98.9%

Details

CWE
CWE-119
Status published
Products (3)
microsoft/office 2003 sp2 (2 CPE variants)
microsoft/works 8.0
microsoft/works 2005
Published Feb 12, 2008
Tracked Since Feb 18, 2026