CVE-2008-4841

EXPLOITED IN THE WILD

Microsoft WordPad - Remote Code Execution via Crafted Word 97 File

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2008-4841 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including securfrog.

AI-analyzed exploit summary The provided entry references an external download for a Wordpad .doc file PoC but contains no actual exploit code or technical details. It relies on an off-site RAR file, which is a common tactic for suspicious or malicious repositories.

Description

The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.

Exploits (1)

exploitdb SUSPICIOUS VERIFIED
by securfrog · textdoswindows
https://www.exploit-db.com/exploits/6560

The provided entry references an external download for a Wordpad .doc file PoC but contains no actual exploit code or technical details. It relies on an off-site RAR file, which is a common tactic for suspicious or malicious repositories.

Classification
Suspicious 90%
Attack Type
Dos
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Windows Wordpad
No auth needed
Prerequisites: Access to the external download link
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (13)

Core 13
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6560
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6050
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32718
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32997
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3390
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-104A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31399
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1021376
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4711
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1024

Scores

EPSS 0.7455
EPSS Percentile 98.9%

Details

VulnCheck KEV 2008-12-10
InTheWild.io 2019-02-26
CWE
CWE-399
Status published
Products (2)
microsoft/wordpad
microsoft/wordpad unknown
Published Dec 10, 2008
Tracked Since Feb 18, 2026