CVE-2008-4841 describes a critical memory corruption vulnerability in the WordPad Text Converter for Word 97 files, affecting Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2. This flaw allows remote attackers to execute arbitrary code by enticing a user to open a specially crafted .doc, .wri, or .rtf file. With a CVSS score of 9.3, it is considered highly severe due to its network attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. The vulnerability was exploited in the wild in December 2008, and while a Proof-of-Concept for a denial-of-service exists, there is no evidence of widespread community discussion or media coverage beyond its initial exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:wordpad:*:*:*:*:*:*:*:* | ||
unknownCPE matchmatch criteria | cpe:2.3:a:microsoft:wordpad:unknown:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.