Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 89.5%; technical severity is CVSS 7.8.
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."
Who should care
- Teams operating Office, Open Xml File Format Converter
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Office, Open Xml File Format Converter is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Microsoft Security patch Ms10 087
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-119
- Affected versions
- Microsoft Office (Version 2003 | Version 2004 | Version 2007 | Version 2008); Microsoft Open Xml File Format Converter (Version -)
- Fixed versions
- No explicit fixed version is currently recorded.
- Published
- 10 November 2010
- Attack vector
- Local
- Privileges required
- None
- User interaction
- Required
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 89.5%
- Signal calculated at 82
External references
- CISA Government advisory CVE-2010-3333
- Secunia Technical reference
- Secunia Technical reference
- Securityreason Technical reference
- Securityfocus Third-party advisory
- Securitytracker Third-party advisory
- Us Cert Government advisory TA10 313A
- Vupen Technical reference
- Oval Cisecurity Technical reference Oval%3Aorg.mitre.oval%3Adef%3A11931