Vulnerability Details CVE-2008-1092
                Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008.  NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.606
                        
                    
                    
                        
                            EPSS Ranking 98.2%
                        
                    
                 
                
                    CVSS Severity
                    
                    
                        
                            CVSS v2 Score 9.3
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2008-1092
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:microsoft:word:2000
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:microsoft:word:2002
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:microsoft:word:2003
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:microsoft:word:2003_sp3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:microsoft:word:2007
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:microsoft:word:2007_sp1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:microsoft:windows_2000:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:microsoft:windows_2003_server:sp1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:microsoft:windows_xp:-