CVE-2010-3334 is a critical remote code execution vulnerability affecting multiple versions of Microsoft Office and the Open XML File Format Converter for Mac. This flaw allows attackers to execute arbitrary code by crafting malicious Office documents that exploit memory corruption within Office Art Drawing records. With a CVSS score of 9.3, it poses a significant risk, requiring medium attack complexity but leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high EPSS and FAUCET risk scores indicate its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp2:*:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.