Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2008-4841 Details

Description

The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://milw0rm.com/sploits/2008-crash.doc.rar CVEExploit
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-010 CVE
http://secunia.com/advisories/32997 CVEVendor Advisory
http://securityreason.com/securityalert/4711 CVE
http://securitytracker.com/id?1021376 CVE

see all 26 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-399Resource Management Errors[email protected]
NVD-CWE-noinfoInsufficient Information to Classify Weakness[email protected]

Affected Products

ProductVersions
microsoft wordpad
unknown

CPE

  • cpe:2.3:a:microsoft:wordpad:*:*:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:wordpad:unknown:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
microsoft windows 2000
All versions

CPE

  • cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*

Remediation

  • No remediation found in references.
microsoft windows server 2003
All versions

CPE

  • cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*

Remediation

  • No remediation found in references.
microsoft windows xp
All versions

CPE

  • cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

9 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2008-4841
NVD Published Date:
Dec 10, 2008
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2008-4841 Details - Not Deferred