Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.541
EPSS Ranking 97.9%