CVE-2008-0118

Microsoft Office - Code Injection

Title source: rule

Description

Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."

Exploits (2)

exploitdb SUSPICIOUS VERIFIED
by Marsu · textlocalwindows
https://www.exploit-db.com/exploits/5320
exploitdb WRITEUP VERIFIED
by anonymous · textdoswindows
https://www.exploit-db.com/exploits/31361

Scores

EPSS 0.7932
EPSS Percentile 99.1%

Details

CWE
CWE-94
Status published
Products (4)
microsoft/office 2000 sp3
microsoft/office 2003 sp2
microsoft/office 2004
microsoft/office xp sp3
Published Mar 11, 2008
Tracked Since Feb 18, 2026