CVE-2008-0118

Microsoft Office 2000/2003/XP, Excel Viewer 2003, Office 2004 for Mac - RCE via Crafted Document

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-0118. PoCs published by Marsu, anonymous.

AI-analyzed exploit summary The provided content lacks actual exploit code and instead points to an external download link, which is a common indicator of a suspicious repository. The description is vague and does not include technical details about the vulnerability.

Description

Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."

Exploits (2)

exploitdb SUSPICIOUS VERIFIED
by Marsu · textlocalwindows
https://www.exploit-db.com/exploits/5320

The provided content lacks actual exploit code and instead points to an external download link, which is a common indicator of a suspicious repository. The description is vague and does not include technical details about the vulnerability.

Classification
Suspicious 90%
Attack Type
Other
Complexity
N/a
Reliability
N/a
Target: Microsoft Office XP SP3
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by anonymous · textdoswindows
https://www.exploit-db.com/exploits/31361

The provided text is a vulnerability description for CVE-2008-0118, a remote memory-corruption issue in Microsoft Office. It lacks actual exploit code but references a binary exploit archive.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Office (unspecified version)
No auth needed
Prerequisites: Victim interaction to open a malicious Office file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5190
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28146
Patch, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-071A.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29321
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=120585858807305&w=2
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0848/references
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019578

Scores

EPSS 0.3484
EPSS Percentile 98.2%

Details

CWE
CWE-94
Status published
Products (4)
microsoft/office 2000 sp3
microsoft/office 2003 sp2
microsoft/office 2004
microsoft/office xp sp3
Published Mar 11, 2008
Tracked Since Feb 18, 2026