peter bassill · operator
$ cve CVE-2010-3333 JSON

CVE-2010-3333 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 89.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS89.5% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-03-24
Public exploityes
Published2010-11-10
Last modified2026-06-16

CISA KEV

NameMicrosoft Office Stack-based Buffer Overflow Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productMicrosoft / Office
Ransomware usenone reported

Affected (2)

VendorProduct
microsoftoffice
microsoftopen xml file format converter

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD