CVE-2010-3333 is a critical stack-based buffer overflow vulnerability affecting multiple versions of Microsoft Office and the Open XML File Format Converter for Mac, allowing remote attackers to execute arbitrary code via specially crafted RTF data. This vulnerability carries a high CVSS score of 7.8, indicating a severe risk with high impact on confidentiality, integrity, and availability, and can be exploited with low attack complexity through user interaction (e.g., opening a malicious file). It is actively exploited in the wild, listed in CISA's KEV catalog, and has extensive public exploit code available, including Metasploit modules and numerous ExploitDB entries, reflecting significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2004:*:*:*:*:macos:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2008:*:*:*:*:macos:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.