← Vulnerability feed

Vulnerability record · CVE-2008-2244 · published 9 July 2008

CVE-2008-2244: Microsoft office word vulnerability

Microsoft · Office Word

Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.

9.3 CVSS 2.0 High EPSS 32% · top 1.7% CWE-399 · CWE-399
9.3CVSS 2.0 base score
32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2244 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-2506Microsoft windows 2000 vulnerabilityInteger overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000…EPSS 31%9.3CVE-2009-3135Microsoft office memory buffer overflow vulnerabilityStack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Off…EPSS 36%9.3CVE-2009-0565Microsoft office memory buffer overflow vulnerabilityBuffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Conve…EPSS 41%9.3CVE-2009-0087Microsoft office word vulnerabilityUnspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and the…EPSS 26%9.3CVE-2009-0088Microsoft office converter pack improper input validation vulnerabilityThe WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly vali…EPSS 28%9.3CVE-2008-4837Microsoft office memory buffer overflow vulnerabilityStack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compa…EPSS 37%9.3CVE-2008-4024Microsoft office code injection vulnerabilityMicrosoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a craft…EPSS 29%9.3CVE-2008-4025Microsoft office memory buffer overflow vulnerabilityInteger overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and S…EPSS 33%

Source: NIST National Vulnerability Database (record CVE-2008-2244), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.