Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-3333

97
FAUCET Score

CVE-2010-3333 is a critical stack-based buffer overflow vulnerability affecting multiple versions of Microsoft Office and the Open XML File Format Converter for Mac, allowing remote attackers to execute arbitrary code via specially crafted RTF data. This vulnerability carries a high CVSS score of 7.8, indicating a severe risk with high impact on confidentiality, integrity, and availability, and can be exploited with low attack complexity through user interaction (e.g., opening a malicious file). It is actively exploited in the wild, listed in CISA's KEV catalog, and has extensive public exploit code available, including Metasploit modules and numerous ExploitDB entries, reflecting significant community and media attention.

Impacted Technologies

VendorProductVersion(s)CPE
2003CPE matchmatch criteria
cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
2004CPE matchmatch criteria
cpe:2.3:a:microsoft:office:2004:*:*:*:*:macos:*:*
2007CPE matchmatch criteria
cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:*
2008CPE matchmatch criteria
cpe:2.3:a:microsoft:office:2008:*:*:*:*:macos:*:*
2010CPE matchmatch criteria
cpe:2.3:a:microsoft:office:2010:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
89.50%
Probability of exploitation in next 30 days
EPSS Percentile
99.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Mar 3, 2022
Metasploit: MS10-087 Microsoft Word RTF pFragments Stack Buffer Overflow (File Format) · Nov 9, 2010
ExploitDB: EDB-24526 · Feb 20, 2013
This CVE's current EPSS score of 0.8950 is in the 100th percentile among its peer group of 11,615 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
labs.idefense.com / intelligence/vulnerabilities/display.php
Broken Link
docs.microsoft.com / en-us/security-updates/securitybulletins/2010/ms10-087
PatchVendor Advisory
secunia.com / advisories/38521
Broken Link
secunia.com / advisories/42144
Broken Link
securityreason.com / securityalert/8293
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11931
Broken Link
securityfocus.com / bid/44652
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
us-cert.gov / cas/techalerts/TA10-313A.html
Third Party AdvisoryUS Government Resource
vupen.com / english/advisories/2010/2923
Broken Link