KEVIntel
7.8
CVSS
High

CVE-2010-3333

PUBLISHED

Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac...

Exploited in the wild Low complexity
Vendor
Microsoft
Product
Office
Published
Nov 10, 2010
EPSS

Description

Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."

cisa metasploit

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2.0 9.3

AV:N/AC:M/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-03-03 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 03, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

ms10_087_rtf_pfragments_bof

metasploit · Created Unknown

Metasploit module for CVE-2010-3333

Sunqiz/CVE-2010-3333-reproduction

github · Created 2022-08-15 06:54:55 UTC · 1 stars

CVE-2010-3333复现

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit