This script is Copyright (C) 2007-2015 Tenable Network Security, Inc.
Arbitrary code can be executed on the remote host through the RichEdit
component provided with Microsoft Windows and Microsoft Office
The remote host contains a version of Microsoft Windows and/or
Microsoft Office that has a vulnerability in the RichEdit component that
could be abused by an attacker to execute arbitrary code on the remote
To exploit this vulnerability, an attacker would need to spend a
specially crafted RTF file to a user on the remote host and lure him
into opening it.
See also :
Microsoft has released a set of patches for Windows 2000, XP and
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 6.9
Public Exploit Available : false