CVE-2012-0177: Microsoft Office

High severity, CVSS 9.3. EPSS: 30.1% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."

Affected products

  • Microsoft Office: version 2007 only
  • Microsoft Works: version 9.0 only
  • Microsoft Works 6-9 File Converter: affected versions not specified

Published 2012-04-10. Last modified 2026-06-16.