CVE-2012-2539
high-risk
Published 2012-12-12
Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."
Do I need to act?
!
84.4% chance of exploitation in next 30 days
EPSS score — higher than 16% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Products (9)
Affected Vendors
References (7)
Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA12-346A.html
Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA12-346A.html
66
/ 100
high-risk
Severity
24/34 · High
Exploitability
27/34 · High
Exposure
15/34 · Moderate